<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I create custom application with destination IP and TCP/UDP port? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6331#M4615</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your requirement to make a simple and new app to find if this is your web-server traffic yes we can do. Create a new APP with the required destination&amp;nbsp; tcp/udp port. Assign this new app in the Application override rule where we provide the source and destination IPs.&lt;/P&gt;&lt;P&gt;By doing so for any further traffic matching the IP's and ports in the App the traffic would match the application override rule and the sessions would show the new app. ( considering the old sessions are timed out, if not we can clear the old ones )&lt;/P&gt;&lt;P&gt;The prior update by kprakash was to intend that the IPs cannot be added in a signature pattern as such.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Jan 2014 15:59:57 GMT</pubDate>
    <dc:creator>Phoenix</dc:creator>
    <dc:date>2014-01-03T15:59:57Z</dc:date>
    <item>
      <title>Can I create custom application with destination IP and TCP/UDP port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6329#M4613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that FW can control application correctly when has L7 signature.&lt;/P&gt;&lt;P&gt;But my customer want to create application signature more simple and easy for internal trust server.&lt;/P&gt;&lt;P&gt;For example, There is 192.168.1.1 web-server. He want to create app "our-web-server" for destination IP and port are 192.168.1.1:80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can FW be available?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 09:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6329#M4613</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2014-01-03T09:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create custom application with destination IP and TCP/UDP port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6330#M4614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Signatures are Layer 7 attributes, and addresses are layer 3 attributes. As per the PANFW session flow,&amp;nbsp; Layer 3 and layer 4 ( port number) checks are performed first before the actual layer 7 checks ( which happens on a different hardware chip, depending on the platform ). Hence you cannot club addresses into the signature. We can configure security polices, or application override policies to control traffic for a specific IP address along with the application ( built in or custom ). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best bet would be to create a custom application. Name it as "our-web-server" for better understanding. Use it in a rule "Our-web-server-rule", and include the IP address and the custom application under it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 13:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6330#M4614</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2014-01-03T13:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create custom application with destination IP and TCP/UDP port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6331#M4615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your requirement to make a simple and new app to find if this is your web-server traffic yes we can do. Create a new APP with the required destination&amp;nbsp; tcp/udp port. Assign this new app in the Application override rule where we provide the source and destination IPs.&lt;/P&gt;&lt;P&gt;By doing so for any further traffic matching the IP's and ports in the App the traffic would match the application override rule and the sessions would show the new app. ( considering the old sessions are timed out, if not we can clear the old ones )&lt;/P&gt;&lt;P&gt;The prior update by kprakash was to intend that the IPs cannot be added in a signature pattern as such.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 15:59:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6331#M4615</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-01-03T15:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create custom application with destination IP and TCP/UDP port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6332#M4616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you looked at the Applocation Override feature in the Policies Tab?&amp;nbsp; What you have described sounds like a perfect match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SKrall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 02:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6332#M4616</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2014-01-05T02:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create custom application with destination IP and TCP/UDP port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6333#M4617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Karthik&lt;/SPAN&gt; , Phoenix and skrall.&lt;/P&gt;&lt;P&gt;I knew that all traffic for some tcp/udp port(tcp/80) will be port base custom application(our-web-server) when create port base custom application without application-override.&lt;/P&gt;&lt;P&gt;I have tested and seen that port base custom application without override is not generated application in traffic log.&lt;/P&gt;&lt;P&gt;The port base custom application with override is generated application is traffic log.&lt;/P&gt;&lt;P&gt;I got it. As Karthik mentioned, L3&amp;amp;L4 check and L7 check are probably different hardware chip.&lt;/P&gt;&lt;P&gt;Where is the application signature? in signature math hw engine? or in security process?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 04:45:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6333#M4617</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2014-01-07T04:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create custom application with destination IP and TCP/UDP port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6334#M4618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why don't you try a custom application base on the host header value as signature?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10652_Capture.PNG.png" style="width: 620px; height: 417px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 13:24:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6334#M4618</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-07T13:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create custom application with destination IP and TCP/UDP port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6335#M4619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Signature matching is done on a different chip or performed on a software thread depending on the platforms. The security policy check for the traffic happens prior to the signature check, and its performed on another chip ( octeon ), before the traffic is fed to the signature matching engine ( chip )&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 16:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-create-custom-application-with-destination-ip-and-tcp-udp/m-p/6335#M4619</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2014-01-07T16:21:47Z</dc:date>
    </item>
  </channel>
</rss>

