<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OS 7.1 blocking telnet over SSL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113921#M45260</link>
    <description>&lt;P&gt;I think when I configure the destination by IP only the rules not match as now I put /32 on the destination IP that made the rule match&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2016 20:39:44 GMT</pubDate>
    <dc:creator>mikealanni</dc:creator>
    <dc:date>2016-09-16T20:39:44Z</dc:date>
    <item>
      <title>OS 7.1 blocking telnet over SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113890#M45253</link>
      <description>&lt;P&gt;We have in-house software that uses secure-telnet port 992 and that has been blocked after the 7.1.4-h2 upgrade. I've created a rule to pass the traffic to the destenation address with any application any service but never help, the logs said reset both by internzone rule, only changing interzone rule to allow will let the application communicate. &amp;nbsp;Even I did appliaction override on the SSL with destinationa port and address not helped me at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please any clue how to fix this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 17:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113890#M45253</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-09-16T17:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: OS 7.1 blocking telnet over SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113899#M45254</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version of PAN-OS you had before?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post screenshot of the policy and deny logs please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 17:39:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113899#M45254</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-09-16T17:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: OS 7.1 blocking telnet over SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113904#M45255</link>
      <description>&lt;P&gt;7.0.5h2&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline"&gt;&lt;img /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5601iA60DD1AD073A2B10/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 17:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113904#M45255</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-09-16T17:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: OS 7.1 blocking telnet over SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113905#M45256</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks. So your traffic is denied by default policy cause it does not match any other policy. Can you show me a policy config pls for this particular session?&amp;nbsp;What was your policy before an upgrade? Did you try to create a rule with SSL app and destination port 992. I understand you have tried&amp;nbsp;any any but l had strange behaviour, similar to yours. So when l created rule to be more specific&amp;nbsp;it worked for me.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 18:29:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113905#M45256</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-09-16T18:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: OS 7.1 blocking telnet over SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113915#M45257</link>
      <description>&lt;P&gt;I tried specific rule to destenation IP and a service with the port on both UDP and TCP, then tried application SSL then tried unknow-tcp and unknown-udp all togehter nothing works. my default inside to outside rule is any application with default application with profiles.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 19:09:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113915#M45257</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-09-16T19:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: OS 7.1 blocking telnet over SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113917#M45258</link>
      <description>&lt;P&gt;Ok.&amp;nbsp;So from what l understood you have a policy inside &amp;gt;outside with application "any" and the service "&lt;SPAN&gt;application-default".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So PAN-OS 7.1 changes the behaviour for the policy with&amp;nbsp;application-default specified. See below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Policy-behavior-change-application-default/ta-p/75664" target="_blank"&gt;https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Policy-behavior-change-application-default/ta-p/75664&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your policy will allow any APPs but only on the default ports. From the logs, we can see that you have SSL as an application but 992 as a port. Default&amp;nbsp;inter-zone has any any that is why it is permitting your traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 19:34:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113917#M45258</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-09-16T19:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: OS 7.1 blocking telnet over SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113921#M45260</link>
      <description>&lt;P&gt;I think when I configure the destination by IP only the rules not match as now I put /32 on the destination IP that made the rule match&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 20:39:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/os-7-1-blocking-telnet-over-ssl/m-p/113921#M45260</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-09-16T20:39:44Z</dc:date>
    </item>
  </channel>
</rss>

