<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Looking for a way to allow an application without allowing all dependencies with no commit warni in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/142879#M48613</link>
    <description>&lt;P&gt;Hi Joshua&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The dependency warning will remain as the dependency has not been met&lt;/P&gt;
&lt;P&gt;You could create a security policy that allows ssh only to a custom category containing all the URL's used by sourceforge:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="url destination.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="url destination.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is slightly different from URL filtering as it uses the category as a layer 3 destination match rather than url filtering&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;alternatively, if you know the sourceforge servers, you could add FQDN objects to the destination&lt;/P&gt;</description>
    <pubDate>Tue, 14 Feb 2017 10:33:13 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-02-14T10:33:13Z</dc:date>
    <item>
      <title>Looking for a way to allow an application without allowing all dependencies with no commit warnings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/142714#M48582</link>
      <description>&lt;P&gt;Issue background:&lt;/P&gt;&lt;P&gt;We have a policy for Application Whitelist of allowed applications on the internet firewall. &amp;nbsp;SourceForge-Base is one of these applications. &amp;nbsp;SourceForge-Base had dependencies on SSL, Web-Browsing, and SSH. &amp;nbsp;We allow SSL and Web-Browsing, but do not wish to allow SSH to the entire outbound internet. &amp;nbsp;Our users traffic works fine with only SSL and Web-Browsing being allowed in conjunction with SourceForge-Base when they access SourceForge. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without knowing the IP ranges utilized by SourceForge to allow that in a separate policy by service port, (also without utilizing SSL decryption so an FQDN is not an option), we have no way to allow the traffic other than by application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to hide or suppress persistent application dependency warnings in specific so that a commit can come back without warnings? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is there a way to allow SSH only if it is used in conjunction with SourceForge-Base, as in SSH being an Implicit Use Application for SourceForge-Base?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/142714#M48582</guid>
      <dc:creator>JoshuaBolin</dc:creator>
      <dc:date>2017-02-13T16:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a way to allow an application without allowing all dependencies with no commit warni</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/142879#M48613</link>
      <description>&lt;P&gt;Hi Joshua&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The dependency warning will remain as the dependency has not been met&lt;/P&gt;
&lt;P&gt;You could create a security policy that allows ssh only to a custom category containing all the URL's used by sourceforge:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="url destination.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="url destination.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is slightly different from URL filtering as it uses the category as a layer 3 destination match rather than url filtering&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;alternatively, if you know the sourceforge servers, you could add FQDN objects to the destination&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 10:33:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/142879#M48613</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-02-14T10:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a way to allow an application without allowing all dependencies with no commit warni</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/143275#M48682</link>
      <description>&lt;P&gt;There's an existing feature request for this capability. &amp;nbsp;Please reach out to your Palo Alto Networks Systems Engineer so your request can be tracked.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 20:35:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/143275#M48682</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-02-15T20:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a way to allow an application without allowing all dependencies with no commit warni</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/143277#M48683</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;&amp;nbsp;&amp;nbsp; Can you provide the FR#?&amp;nbsp; That will save so much time for my SE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;E&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 20:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/143277#M48683</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2017-02-15T20:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a way to allow an application without allowing all dependencies with no commit warni</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/143286#M48684</link>
      <description>&lt;P&gt;Depending on the exact use case, I'd look at: 1887, 2689, 4131&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 21:46:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-a-way-to-allow-an-application-without-allowing-all/m-p/143286#M48684</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-02-15T21:46:17Z</dc:date>
    </item>
  </channel>
</rss>

