<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Service port to application help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/120732#M45969</link>
    <description>&lt;P&gt;You are the man ! So If I understand correctly, the "specific application - rule", I need to put above the "any application - rule" and see if&amp;nbsp;&lt;SPAN&gt;"any application - rule" still getting hit? If not then I can delete this. Right?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Oct 2016 10:12:54 GMT</pubDate>
    <dc:creator>ghostrider</dc:creator>
    <dc:date>2016-10-24T10:12:54Z</dc:date>
    <item>
      <title>Service port to application help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/120579#M45948</link>
      <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We migrated Juniper netscreen firewall to PA. I am just struggling to make application based policies. User just send the ports to make security policies. Like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- Allow port tcp 1549 on mysql db&lt;/P&gt;&lt;P&gt;2- Allow https://ebs:8000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How I can handle this to put application only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly help me with best practice with PA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GR&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 21:17:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/120579#M45948</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-22T21:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Service port to application help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/120611#M45954</link>
      <description>&lt;P&gt;Just create a policy with application and service as those specific port (application any, service tcp1549), run it for few hours|days|weeks and review the traffic log to check what application(s) are getting identify. &amp;nbsp; Once you are comfortable, create another rule with those application(s) identify and service port (for example, application mysql, service tcp 1549 {since mysql default port is tcp 3306}) and place the newly created specific application rule on the existing application any, service specific port rule. &amp;nbsp; Check again if the newly created rule missed any application and repeat the process until you are comfortable, and disable the service only rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 23:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/120611#M45954</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-10-22T23:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Service port to application help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/120732#M45969</link>
      <description>&lt;P&gt;You are the man ! So If I understand correctly, the "specific application - rule", I need to put above the "any application - rule" and see if&amp;nbsp;&lt;SPAN&gt;"any application - rule" still getting hit? If not then I can delete this. Right?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 10:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/120732#M45969</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-24T10:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Service port to application help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/121164#M46023</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42397"&gt;@ghostrider&lt;/a&gt; &amp;nbsp; That is correct. &amp;nbsp;Hope this helps..&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 14:18:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/121164#M46023</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-10-25T14:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Service port to application help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/121513#M46054</link>
      <description>&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 16:19:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-port-to-application-help/m-p/121513#M46054</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-26T16:19:30Z</dc:date>
    </item>
  </channel>
</rss>

