<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application vs Services in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147214#M49337</link>
    <description>&lt;P&gt;Let me give you other example ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Web server IP 20.1.1.2 can be accessed through port 8020 , so i added it on service field and it is working fine&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but what if i need to ping server as well ? so when i added ping to application , it is failed for both web browsing and ping&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Mar 2017 17:14:10 GMT</pubDate>
    <dc:creator>NetworkGeek</dc:creator>
    <dc:date>2017-03-11T17:14:10Z</dc:date>
    <item>
      <title>Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147191#M49330</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have probolem with dealing with security policy ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i need to allow telnet to specific ports range (2001 - 2005) but by defining them at services field it is working fine but i cant use ping or any other applications even my application foedl is (ANY) , so wondering what is difference between both of them and what i do if want to enable ping and telnet tp sepcific ports at same time ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 14:17:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147191#M49330</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-11T14:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147209#M49333</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you add "ping" and "ICMP" application within the same policy as telnet? Not sure but ping is not using any ports so maybe your policy is not matching because of this. Create a test policy purely for&amp;nbsp;&lt;SPAN&gt;"ping" and "ICMP" applications with services as "any" and test&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 15:55:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147209#M49333</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-11T15:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147211#M49334</link>
      <description>&lt;P&gt;Yes i can ping when use "Ping" at application field with "Any" at services .. But this is not what i want as i need to enable both ping and telnet to sepcific ports&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so how can i combine between services and application at one policy ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 16:58:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147211#M49334</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-11T16:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147214#M49337</link>
      <description>&lt;P&gt;Let me give you other example ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Web server IP 20.1.1.2 can be accessed through port 8020 , so i added it on service field and it is working fine&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but what if i need to ping server as well ? so when i added ping to application , it is failed for both web browsing and ping&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 17:14:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147214#M49337</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-11T17:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147216#M49339</link>
      <description>&lt;P&gt;What PAN-OS are you on? The weird&amp;nbsp;thing when you are adding an additional application to the&amp;nbsp;policy web browsing fails :0 You sure you accessing the web-browser on custom port when it is fails?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 18:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147216#M49339</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-11T18:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147217#M49340</link>
      <description>&lt;P&gt;I`m suing version 6 and tried on version 7 as well&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after second test , it is working now but no Ping !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application field : &amp;nbsp;ICMP,PING ,WEB-BROWSING&lt;/P&gt;&lt;P&gt;Services field: Port 8020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so now i can access web server on 8020 only but i can`t ping it&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 17:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147217#M49340</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-11T17:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147221#M49342</link>
      <description>&lt;P&gt;As l said earlier ping doesn't use any port, but your policy has criteria on service&amp;nbsp;to match specific port. My guess ping is not matching your policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 18:05:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147221#M49342</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-11T18:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147222#M49343</link>
      <description>&lt;P&gt;Ok , is ther any workaround for this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 18:07:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147222#M49343</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-11T18:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147223#M49344</link>
      <description>&lt;P&gt;As per my previous comment add same rule for ping but with "any" as a service and put it above already existing rule for web-browsing or use service "any" in the&amp;nbsp;already existing rule (less secure but your web server will only accept connection on the&amp;nbsp;port you specified anyway).&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2017 11:51:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147223#M49344</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-12T11:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147251#M49350</link>
      <description>&lt;P&gt;I guess it will not provide any security , but still option&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2017 05:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147251#M49350</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-12T05:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147285#M49357</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will provide still based on your&amp;nbsp;others criterias but not based on the destination port.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2017 11:59:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147285#M49357</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-12T11:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147287#M49358</link>
      <description>&lt;P&gt;Yes exactly , totally right&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2017 13:54:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147287#M49358</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-12T13:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147371#M49381</link>
      <description>&lt;P&gt;the application and service fields are mutually inclusive (like an AND operation)&lt;/P&gt;

&lt;P&gt;if you have&lt;/P&gt;

&lt;P&gt;apps web-browsing, telnet , ping&amp;nbsp;&lt;/P&gt;

&lt;P&gt;service 8020&lt;/P&gt;

&lt;P&gt;this means the applications must match web-browsing or telnet &amp;nbsp;or ping AND their destination port &lt;STRONG&gt;must&lt;/STRONG&gt; be 8020.&lt;/P&gt;

&lt;P&gt;so if you add ping in a policy with a service set to a specific&amp;nbsp;port, ping will fail as it can not match the destination port. any application not matching the destination port of 8020 will also fail&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;you'll need to create separate policies so ping can be set to application-default (because, if ping does match a port, something is terribly wrong)&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 09:17:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/147371#M49381</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-13T09:17:16Z</dc:date>
    </item>
  </channel>
</rss>

