<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question about application group and custom service group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-application-group-and-custom-service-group/m-p/118519#M45639</link>
    <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First off I appologize if this question has been answered before.&lt;/P&gt;&lt;P&gt;I have a question regarding the use of application groups and custom service groups in the same security policy. Can traffic identified in the application group use a non standard port that is defined in the custom service group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, Can traffic identified as kerberos in an application group use a non-standard port say 555 which is defined in the custom service group of the policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would behaviour be different if I use application-default as the service in the policy which has application group? Can traffic identified as kerberos use the port UDP 123 since theres the app-id ntp in the same application group as kerberos?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Fri, 07 Oct 2016 21:33:12 GMT</pubDate>
    <dc:creator>jmathew</dc:creator>
    <dc:date>2016-10-07T21:33:12Z</dc:date>
    <item>
      <title>Question about application group and custom service group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-application-group-and-custom-service-group/m-p/118519#M45639</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First off I appologize if this question has been answered before.&lt;/P&gt;&lt;P&gt;I have a question regarding the use of application groups and custom service groups in the same security policy. Can traffic identified in the application group use a non standard port that is defined in the custom service group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, Can traffic identified as kerberos in an application group use a non-standard port say 555 which is defined in the custom service group of the policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would behaviour be different if I use application-default as the service in the policy which has application group? Can traffic identified as kerberos use the port UDP 123 since theres the app-id ntp in the same application group as kerberos?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 21:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-application-group-and-custom-service-group/m-p/118519#M45639</guid>
      <dc:creator>jmathew</dc:creator>
      <dc:date>2016-10-07T21:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Question about application group and custom service group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-application-group-and-custom-service-group/m-p/118561#M45640</link>
      <description>&lt;P&gt;I think I found the answer to this but want to confirm &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-message-heading"&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-standard"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-20 lia-quilt-column-left"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-left"&gt;&lt;DIV class="lia-message-author"&gt;&lt;SPAN class="author-by"&gt;by&lt;/SPAN&gt; &lt;SPAN class="UserName lia-user-name lia-user-rank-L4-Transporter"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12067" target="_self"&gt;&lt;SPAN class=""&gt;minow&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;DIV class="lia-message-post-edit-date-wrapper"&gt;on &lt;SPAN class="DateTime lia-message-posted-on lia-component-common-widget-date"&gt;&lt;SPAN class="local-date"&gt;‎07-01-2015&lt;/SPAN&gt; &lt;SPAN class="local-time"&gt;05:48 AM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-post-edit-date-wrapper"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-body"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;another important thing to put in mind&lt;/P&gt;&lt;P&gt;1) if you choose application-default this will cause that only the identified application will be allowed on this port for example it you put ssh and web-browsing on the same rule, web-browsing wont be allowed on port 22 but if you will put on the service tab tcp-80 and tcp-22 both ssh and web-browsing will be allowed on both of the port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) another thing is if you put a non tcp/udp application and you do specify a specific service this application wont be matched on that rule&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 07 Oct 2016 21:54:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-application-group-and-custom-service-group/m-p/118561#M45640</guid>
      <dc:creator>jmathew</dc:creator>
      <dc:date>2016-10-07T21:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Question about application group and custom service group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-application-group-and-custom-service-group/m-p/118681#M45655</link>
      <description>&lt;P&gt;indeed,application-default will enforce the default ports per application, so if you have a group of apps in a policy, they will not be able to use eachother's ports (ftp on port 80 will not work if app-default is enabled)&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 08:30:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-application-group-and-custom-service-group/m-p/118681#M45655</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-10T08:30:20Z</dc:date>
    </item>
  </channel>
</rss>

