<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using application-default with application override in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5732#M4188</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt; color: #000000;"&gt;According to product help for application-default: &lt;SPAN style="line-height: 1.5em;"&gt;The selected applications are allowed or denied only on their default &lt;/SPAN&gt;&lt;SPAN class="Bold" style="line-height: 1.5em;"&gt;ports defined by Palo Alto Networks&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em;"&gt;. This option is recommended for allow policies because it prevents applications from running on unusual ports and protocols, which if not intentional, can be a sign of undesired application behavior and usage. Note that when you use this option, the device still checks for all applications on all ports, &lt;SPAN style="color: #ff0000;"&gt;&lt;EM&gt;but with this configuration, applications are only allowed on their default ports/protocols&lt;/EM&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt; color: #000000;"&gt;When I use an application override rule, can I still use application-default or do I need to use ANY?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 May 2013 21:26:20 GMT</pubDate>
    <dc:creator>nthen</dc:creator>
    <dc:date>2013-05-28T21:26:20Z</dc:date>
    <item>
      <title>Using application-default with application override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5732#M4188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt; color: #000000;"&gt;According to product help for application-default: &lt;SPAN style="line-height: 1.5em;"&gt;The selected applications are allowed or denied only on their default &lt;/SPAN&gt;&lt;SPAN class="Bold" style="line-height: 1.5em;"&gt;ports defined by Palo Alto Networks&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em;"&gt;. This option is recommended for allow policies because it prevents applications from running on unusual ports and protocols, which if not intentional, can be a sign of undesired application behavior and usage. Note that when you use this option, the device still checks for all applications on all ports, &lt;SPAN style="color: #ff0000;"&gt;&lt;EM&gt;but with this configuration, applications are only allowed on their default ports/protocols&lt;/EM&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt; color: #000000;"&gt;When I use an application override rule, can I still use application-default or do I need to use ANY?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 21:26:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5732#M4188</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-05-28T21:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Using application-default with application override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5733#M4189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you create a custom application you can also specify the default ports that the application will use.&amp;nbsp; When you create or modify a custom application navigate to the Advanced tab and under the Defaults section&amp;nbsp; you can define the default port definitions.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="app_port.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6698_app_port.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;When the security policy is defined with the custom application, and service is set to application-default, the firewall will use the application's defined default ports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hope this helps.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 21:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5733#M4189</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2013-05-28T21:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using application-default with application override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5734#M4190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With Application Override,firewall would be bypassing Signature based application Identification.&lt;/P&gt;&lt;P&gt;If the Custom-App defined includes the default ports used by the application,you should be able to use app-default.&lt;/P&gt;&lt;P&gt;I would suggest using any as the traffic is already being allowed based on ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ref&amp;nbsp; : &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;https://live.paloaltonetworks.com/docs/DOC-1071&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 21:35:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5734#M4190</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-05-28T21:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Using application-default with application override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5735#M4191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;When you are using application override you are create a customer app with a port number defined in it.&lt;/P&gt;&lt;P&gt;Moreover you also create an services and select that particular service in that application.&lt;/P&gt;&lt;P&gt;Since when app override is created it does not pass through firewalls app engine i think it would be best to either user any or define the service.&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 21:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5735#M4191</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-05-28T21:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Using application-default with application override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5736#M4192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These posts are helpful.&amp;nbsp; I'll go into a bit more detail to see how others would go about it.&amp;nbsp; We use EDI to send information to and from our mainframe with vendors.&amp;nbsp; The EDI uses the AS2 application with Palo Alto detects.&amp;nbsp; However our port is not in the list of default ports for the application.&amp;nbsp; The default ports for this app are 80,443,4080,5443.&amp;nbsp; We use TCP 5060.&amp;nbsp; I was first thinking an application override policy and give a different port to the app, but based on the comments above that may not be such a good idea.&amp;nbsp; I can see using ANY as the service, but that could potentially open other ports.&amp;nbsp; In this case would it be better to use something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For traffic coming from outside to inside to my EDI server, set the application to AS2.&amp;nbsp; Since my port is 5060 do not use ANY but create a custom service for 5060.&amp;nbsp; This way I am only allow AS2 on 5060 and nothing more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would this be a better option?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 13:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5736#M4192</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-05-29T13:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Using application-default with application override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5737#M4193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Generally speaking, "Application Override" is a tool you can use to override what application the firewall detects.&amp;nbsp; In your case here, the firewall is already detecting the application properly as AS2, so you don't need to use an Application Override.&amp;nbsp; Keep in mind that all of Palo Alto's "AppIDs" are running on all ports at all times - so it has the ability to detect the AS2 application even on port 5060.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if you create a rule that says "permit outbound AS2 on application-default", that won't work because you're running this application on a non-standard port.&amp;nbsp; Your suggestion of creating a security policy rule that permits application AS2 on a custom service port (5060) are correct.&amp;nbsp; That would achieve what you're looking for - allowing AS2 on port 5060 and nothing more.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 14:16:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5737#M4193</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-05-29T14:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Using application-default with application override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5738#M4194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perfect!&amp;nbsp; This is a big help.&amp;nbsp; Thanks for your input!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 14:19:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-application-default-with-application-override/m-p/5738#M4194</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-05-29T14:19:27Z</dc:date>
    </item>
  </channel>
</rss>

