<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom Application and TAC in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120601#M45951</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I request to TAC to create custom application or I have to do by my self? I found this but I guest it is for public application not for internal.&lt;/P&gt;&lt;P&gt;&lt;A href="http://researchcenter.paloaltonetworks.com/submit-an-application/" target="_blank"&gt;http://researchcenter.paloaltonetworks.com/submit-an-application/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 22 Oct 2016 22:00:05 GMT</pubDate>
    <dc:creator>ghostrider</dc:creator>
    <dc:date>2016-10-22T22:00:05Z</dc:date>
    <item>
      <title>Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120601#M45951</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I request to TAC to create custom application or I have to do by my self? I found this but I guest it is for public application not for internal.&lt;/P&gt;&lt;P&gt;&lt;A href="http://researchcenter.paloaltonetworks.com/submit-an-application/" target="_blank"&gt;http://researchcenter.paloaltonetworks.com/submit-an-application/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 22:00:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120601#M45951</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-22T22:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120734#M45971</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will have to create it yourself. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;The form is to submit a new public application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This might be useful :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Notes/Custom-Application-Signatures/ta-p/58625" target="_blank"&gt;Custom-Application-Signatures&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kim&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 10:16:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120734#M45971</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-10-24T10:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120751#M45974</link>
      <description>&lt;P&gt;Hello Kiwi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So custom application is requried only when I see the unknown applicaiton in the logs? In which case I will create the app override?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 11:26:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120751#M45974</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-24T11:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120973#M46008</link>
      <description>&lt;P&gt;Right, custom applications are only needed if your traffic is unknown to the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application override is different. &amp;nbsp;This prevents the upper level inspections and you would use this when the PA is incorrectly categorizing your traffic as a known application. &amp;nbsp;You override the categorization using these rules.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 22:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/120973#M46008</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-10-24T22:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/121515#M46055</link>
      <description>&lt;P&gt;Thank you steve. But in PA documents and video, &amp;nbsp;I saw they for unknown application, they are using appoverrride&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 16:21:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/121515#M46055</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-26T16:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/122228#M46118</link>
      <description>&lt;P&gt;Do you have the link for the video handy so I can understand the context of what they are doing there?&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2016 11:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/122228#M46118</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-10-29T11:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/122280#M46125</link>
      <description>&lt;P&gt;Hello Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-an-Application-Override-Policy/ta-p/60044" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-an-Application-Override-Policy/ta-p/60044&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;An application override could be used wilth custom internal applications that use non-standard port numbers or internal applications classified by the firewall as "unknown" for which custom definitions have been created&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2016 15:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/122280#M46125</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-29T15:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124437#M46313</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas﻿&lt;/a&gt;&amp;nbsp;Could you please see this video, they are saying for unknown-tcp and udp you can use app-override&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=CwXdWJpw0UY" target="_blank"&gt;https://www.youtube.com/watch?v=CwXdWJpw0UY&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2016 20:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124437#M46313</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-06T20:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124580#M46327</link>
      <description>&lt;P&gt;app override is used to prevent the AppID engine from kicking in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it is not necessary to use this for a custom application to work, but can be useful in certain scenarios:&lt;/P&gt;
&lt;P&gt;-AppID wants to identify an application and you &lt;EM&gt;need&lt;/EM&gt; it to be something else (there could be a custom application mechanism that conflicts with how it's parent application is supposed to work)&lt;/P&gt;
&lt;P&gt;-the app is unknown so AppID will not be useful&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for unknown applications, app override is not mandatory, it simply preserves resources by disabling AppID for a particular session&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 10:32:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124580#M46327</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-07T10:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124594#M46333</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;thank you. So for unknown applicaiton, either we can do app-override or make custom application. If traffic matches with built in application (worngly) and custom application as well, then PA will match with what? I mean builtin application or custom application?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciated your reply&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 11:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124594#M46333</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-07T11:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124629#M46343</link>
      <description>&lt;P&gt;the normal flow would be like this (for example, there is a web-app you want to identify)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you create a custom app that matches a certain signature&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;without app override&lt;/P&gt;
&lt;P&gt;AppID will start processing a new session&lt;/P&gt;
&lt;P&gt;at the http/1.1 it will likely first identify web-browsing,&lt;/P&gt;
&lt;P&gt;in one of the next packets, your signature would be hit and the app would change into your custom application&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;with app override:&lt;/P&gt;
&lt;P&gt;a new session is received matching the app override rule, custom application is assigned, no logic is checked (basically like a traditional firewall without intelligence)&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 13:31:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124629#M46343</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-07T13:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124642#M46347</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;Thanks. Sorry for my ignorance but need to ask, so for my custom signature to work, I need to explicityly allow web-browing in security rule along with custom app or no need?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 14:49:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124642#M46347</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-07T14:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124651#M46349</link>
      <description>&lt;P&gt;no problem!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if your custom app relies on web-browsing, yes (eg you're hosting a website and want it identified as a specific app)&lt;/P&gt;
&lt;P&gt;if your custom app is something written from scratch, not running on top of a known protocol: no&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 15:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124651#M46349</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-07T15:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124757#M46364</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;so it means for all custom web applications, web-browsing has to be allowed with custom application?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 20:10:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124757#M46364</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-07T20:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124889#M46374</link>
      <description>&lt;P&gt;yes, but it doesn't need to be in the same rule, as long as web-browsing is allowed somewhere in the policy, it will work&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 08:52:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124889#M46374</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-08T08:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124899#M46378</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;thanks. what about client server applications (tcp/udp) custom applicaitons, there is any parent tcp/udp application like web-browsing for web-application?&lt;/P&gt;&lt;P&gt;Also for build custom application in a rule, should I ask application to check all the funtionalities of application while doing the packet capture? I mean how much traffic need to pass for the rule to build custom application. Appreciated your recommendation&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 09:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124899#M46378</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-08T09:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124907#M46382</link>
      <description>&lt;P&gt;have you checked out these articles ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635" target="_blank"&gt; Getting Started: Custom applications and app override&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Custom-Vulnerability/ta-p/71603" target="_blank"&gt; Tips &amp;amp; Tricks: Custom Vulnerability&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the amount of data needed for your custom application depends on how your app was created&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;normally AppID kicks in before the first 2000bytes/8packets but for web-based applications, AppID keeps scanning longer so if your application can only be identified by some string of data in the payload of a web-based session, you can use that to trigger. You will need to decide how long your packetcapture needs to be to get to the information you want to use to create a custom app as in the end you decide which 'string' will need to be matched&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 10:18:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/124907#M46382</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-08T10:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/125065#M46392</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;The system automatically doing the packet capture for unknown-tcp. Is that capture sufficient for make custom app?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 20:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/125065#M46392</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-08T20:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application and TAC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/125258#M46410</link>
      <description>&lt;P&gt;maybe &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; it will capture the packets it cannot identify which will likely contain the signature you want to be looking for, but I would recommend setting up a proper packetcapture to make sure you have a good view of what packets are exchanged and the payload therein&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2016 13:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-and-tac/m-p/125258#M46410</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-09T13:09:45Z</dc:date>
    </item>
  </channel>
</rss>

