<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Behaviour app override in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/78967#M43085</link>
    <description>&lt;P&gt;Hi, we are having an issue using app override.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) We have created a custom app for Oracle (without timeout). Using these ports: tcp1521-1541.&lt;/P&gt;
&lt;P&gt;This is the config&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="App customized.jpg" style="width: 749px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4246i65532D2D260F476C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="App customized.jpg" alt="App customized.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the app override policy:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appoverride.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4247i710E0101CAF1181B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="appoverride.jpg" alt="appoverride.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the security policy (app any and ports involved in this app 1533 and 60xxx):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline"&gt;&lt;img /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reglaaplica.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4250i5DF21CC555181B6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="reglaaplica.jpg" alt="reglaaplica.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Service profile for ports open in this ORACLE connection (1023-65535)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ports high.jpg" style="width: 262px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4254i6AF937A7417713D4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ports high.jpg" alt="ports high.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After doing all these changes, the Oracle (custom app) connections stopped working so we check the&amp;nbsp;monitor traffic logs and we saw this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitor problems.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4251i42FBF7AEED1B6A10/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="monitor problems.jpg" alt="monitor problems.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;Well, we decided to configure a source filter in our app override policy, in order not matching "app override" policy with any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appoverridebien.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4252i5A5C487C4D6E10B6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="appoverridebien.jpg" alt="appoverridebien.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;After doing that we realised that these Oracle connections open another ports in range 606xx, but using app override these others ports didnt appear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitorbien.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4256i25D1AFAE44CE43A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="monitorbien.jpg" alt="monitorbien.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the this screenshot we can see what monitor shows using app_overrise and Oracle default. Using our custom app (Iracle_1521_1541) is taking the connection in ports 1533 fine but not another ports are appearing so its not working fine.&lt;/P&gt;
&lt;P&gt;At 13:17:00 we disabled app override policy and it started working.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So its like using app override for this custom app, if another ports in the connections are used its not working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="global.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4255iD4F093CFC30BF8B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="global.jpg" alt="global.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why using our custom app we cant see the ports open over this Oracle_custom connection??&amp;nbsp;How could we solve this???&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jun 2016 18:39:11 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2016-06-01T18:39:11Z</dc:date>
    <item>
      <title>Behaviour app override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/78967#M43085</link>
      <description>&lt;P&gt;Hi, we are having an issue using app override.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) We have created a custom app for Oracle (without timeout). Using these ports: tcp1521-1541.&lt;/P&gt;
&lt;P&gt;This is the config&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="App customized.jpg" style="width: 749px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4246i65532D2D260F476C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="App customized.jpg" alt="App customized.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the app override policy:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appoverride.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4247i710E0101CAF1181B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="appoverride.jpg" alt="appoverride.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the security policy (app any and ports involved in this app 1533 and 60xxx):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline"&gt;&lt;img /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reglaaplica.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4250i5DF21CC555181B6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="reglaaplica.jpg" alt="reglaaplica.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Service profile for ports open in this ORACLE connection (1023-65535)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ports high.jpg" style="width: 262px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4254i6AF937A7417713D4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ports high.jpg" alt="ports high.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After doing all these changes, the Oracle (custom app) connections stopped working so we check the&amp;nbsp;monitor traffic logs and we saw this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitor problems.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4251i42FBF7AEED1B6A10/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="monitor problems.jpg" alt="monitor problems.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;Well, we decided to configure a source filter in our app override policy, in order not matching "app override" policy with any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appoverridebien.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4252i5A5C487C4D6E10B6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="appoverridebien.jpg" alt="appoverridebien.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;After doing that we realised that these Oracle connections open another ports in range 606xx, but using app override these others ports didnt appear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitorbien.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4256i25D1AFAE44CE43A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="monitorbien.jpg" alt="monitorbien.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the this screenshot we can see what monitor shows using app_overrise and Oracle default. Using our custom app (Iracle_1521_1541) is taking the connection in ports 1533 fine but not another ports are appearing so its not working fine.&lt;/P&gt;
&lt;P&gt;At 13:17:00 we disabled app override policy and it started working.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So its like using app override for this custom app, if another ports in the connections are used its not working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="global.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4255iD4F093CFC30BF8B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="global.jpg" alt="global.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why using our custom app we cant see the ports open over this Oracle_custom connection??&amp;nbsp;How could we solve this???&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 18:39:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/78967#M43085</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-06-01T18:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Behaviour app override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/78992#M43094</link>
      <description>&lt;P&gt;hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;looks like your oracle deployment may have been customized somehow to use other ports than expected&lt;/P&gt;
&lt;P&gt;can you try this: set the custom app with 'parent app' oracle, set the ports to tcp/dynamic and disable app override:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-06-02_09-48-44.jpg"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="2016-06-02_09-48-44.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 07:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/78992#M43094</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-02T07:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Behaviour app override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/78999#M43099</link>
      <description>&lt;P&gt;But if i disable "app override", the custom app will not&amp;nbsp;applied, right??&lt;/P&gt;
&lt;P&gt;With app override policy i say what source/destination range will ovewrite the app.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;should i configure the ports in app like this??:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capturauna.JPG" style="width: 758px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4263iB1281180F44EA98B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capturauna.JPG" alt="Capturauna.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the previous changes will affect to another apps???&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks a lot reaper.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 10:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/78999#M43099</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-06-02T10:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Behaviour app override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/79005#M43102</link>
      <description>&lt;P&gt;app override is not required if you only want to identify an application differently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;App override forces AppID to not inspect certain sessions and instead acts as a stateful firewall. it disabled AppID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a custom app without override let's AppID do it's job of inspecting the session and you tell it to identify an application differently. since oracle is set as parent app, it should only apply to sessions identified as oracle&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;usually your method should work just fine, but the fact that it doesn't and without the override it starts using different ports may mean your deployment may be somewhat special and the heavy handed approach with app override might break something&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'd start with only tcp/dynamic, once you get it to work you can tone that down to the actual set of ports you would like to use (you could also add the tcp/606** instead of dynamic if you prefer)&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 11:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/behaviour-app-override/m-p/79005#M43102</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-02T11:33:36Z</dc:date>
    </item>
  </channel>
</rss>

