<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What's the best way to permit app on non-standard port? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/79031#M43115</link>
    <description>&lt;P&gt;In the custom app definition under the Advanced tab it's set to port and tcp/8080. &amp;nbsp;If there's another place to define the port I don't know about it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've opened a support ticket, then promptly took some time off so haven't talked to them yet. &amp;nbsp;Hopefully tomorrow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jun 2016 17:52:06 GMT</pubDate>
    <dc:creator>DaveNoonan</dc:creator>
    <dc:date>2016-06-02T17:52:06Z</dc:date>
    <item>
      <title>What's the best way to permit app on non-standard port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/78705#M43005</link>
      <description>&lt;P&gt;For instance, web browsing on port 8080.&amp;nbsp; I don't want to just set the service as I also want to use port 80 and there are other apps in the rule and I'd like to use app-default as the service.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I defined a custom app with web-browsing as the parent and the port as tcp/8080.&amp;nbsp; That worked until I upgraded to 7.1.2 and then it broke.&amp;nbsp; I'm aware that 7.1 changed the behavior when the App = Any and the Svc = App-Default, but for my custom app, brilliantly named "web-browsing_8080", the default port is 8080, so why it no work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BTW, in my mind this could be as simple as cloning the default web-browsing app and changing the port number but for unknown reasons that isn't allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-- Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 18:41:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/78705#M43005</guid>
      <dc:creator>DaveNoonan</dc:creator>
      <dc:date>2016-05-26T18:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way to permit app on non-standard port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/78716#M43011</link>
      <description>&lt;P&gt;Hi Dave&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this proxy traffic or regular web-browsing on http ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it's proxy sessions (web-browsing directed at a proxy server), there's an app for that! Add http-proxy to your policy and you're good to go&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it's regular web-browsing on a different port, create a custom application with the desired attributes and set the parent app to web-browsing&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-05-27_10-10-00.jpg"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="2016-05-27_10-10-00.jpg" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-05-27_10-10-28.jpg"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="2016-05-27_10-10-28.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 08:14:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/78716#M43011</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-27T08:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way to permit app on non-standard port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/78731#M43018</link>
      <description>&lt;P&gt;Yeah, that's what I did and it worked until I updated to 7.1.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adding a little more info the rule has an app group and that app group includes both web-browsing and my custom app (web-browsing_8080) and the service was set to app-default.&amp;nbsp; That worked until the upgrade at which point I had to change the service to ANY as a quick fix.&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 12:23:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/78731#M43018</guid>
      <dc:creator>DaveNoonan</dc:creator>
      <dc:date>2016-05-27T12:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way to permit app on non-standard port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/78793#M43035</link>
      <description>&lt;P&gt;in 7.1 the default behavior of 'application-default' has changed : &lt;A href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Policy-behavior-change-application-default/ta-p/75664" target="_blank"&gt;PAN-OS 7.1 Policy behavior change application-default&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;so that it now enforces default ports for 'implied' applications (so 'any' app with app-default will allow all apps but only on their default ports)&lt;/P&gt;
&lt;P&gt;did you make sure to define tcp/8080 as the default port for your custom application ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you may wanna reach out to support to make sure there isn't an issue with this deployment&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2016 09:13:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/78793#M43035</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-30T09:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way to permit app on non-standard port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/79031#M43115</link>
      <description>&lt;P&gt;In the custom app definition under the Advanced tab it's set to port and tcp/8080. &amp;nbsp;If there's another place to define the port I don't know about it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've opened a support ticket, then promptly took some time off so haven't talked to them yet. &amp;nbsp;Hopefully tomorrow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 17:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-best-way-to-permit-app-on-non-standard-port/m-p/79031#M43115</guid>
      <dc:creator>DaveNoonan</dc:creator>
      <dc:date>2016-06-02T17:52:06Z</dc:date>
    </item>
  </channel>
</rss>

