<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 7.1 default behavior changes in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155848#M51203</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is from KB:&lt;/P&gt;&lt;P&gt;&amp;nbsp;-----------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In earlier PAN-OS release versions, the Service setting 'application-default' was not enforced when configured with the Application setting Any.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;-----------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So prior 7.1 if your policy has an application option configured as "any" all applications were permitted (even on none default ports).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After 7.1 if your policy has an application option configured as any and services "application-default", your all application will be permitted on standard (default) ports ONLY. Let's say if you are running a web server on port 8080, traffic will not match and most likely will be denied (al least l had this scenario :D).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2017 21:07:24 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-05-09T21:07:24Z</dc:date>
    <item>
      <title>7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155827#M51198</link>
      <description>&lt;P&gt;So I was reading about OS 7.1 because I am planning on upgrading from 7.0.12 to 7.1 and found some information of the default behavior of app-id&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appid.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9180iC3104D834E509DBB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="appid.PNG" alt="appid.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 20:10:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155827#M51198</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-05-09T20:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155833#M51199</link>
      <description>&lt;P&gt;Yep correct:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Policy-behavior-change-application-default/ta-p/75664" target="_blank"&gt;https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Policy-behavior-change-application-default/ta-p/75664&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 20:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155833#M51199</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-09T20:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155837#M51200</link>
      <description>&lt;P&gt;So how is that any different that it used to be&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 20:47:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155837#M51200</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-05-09T20:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155839#M51201</link>
      <description>&lt;P&gt;my other question is if it is a lot different is it going to break anything? How can I check to see what it may break&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 20:49:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155839#M51201</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-05-09T20:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155848#M51203</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is from KB:&lt;/P&gt;&lt;P&gt;&amp;nbsp;-----------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In earlier PAN-OS release versions, the Service setting 'application-default' was not enforced when configured with the Application setting Any.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;-----------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So prior 7.1 if your policy has an application option configured as "any" all applications were permitted (even on none default ports).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After 7.1 if your policy has an application option configured as any and services "application-default", your all application will be permitted on standard (default) ports ONLY. Let's say if you are running a web server on port 8080, traffic will not match and most likely will be denied (al least l had this scenario :D).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 21:07:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155848#M51203</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-09T21:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155958#M51222</link>
      <description>&lt;P&gt;I was operating under that thought that thats how it has always worked and I don't see it as a change. So are you saying application default was not really only the standard ports it was more like an any&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 13:09:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155958#M51222</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-05-10T13:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155963#M51223</link>
      <description>&lt;P&gt;Correct, before 7.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;before 7.1 application "any" = services "application-default" or "any" was the same thing and was allowing&amp;nbsp;any app on any port&lt;/P&gt;&lt;P&gt;after 7.1&amp;nbsp;&lt;SPAN&gt;application "any" = services "application-default" &amp;nbsp;allows app only on the default ports, if services "any" then on any port.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 13:57:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155963#M51223</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-10T13:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155966#M51224</link>
      <description>&lt;P&gt;so application-default was really an any?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 14:00:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155966#M51224</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-05-10T14:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155967#M51225</link>
      <description>&lt;P&gt;Yes, correct before 7.1 services application-defaul=any BUT only if your&amp;nbsp;policy has the application tab set to any.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 14:03:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155967#M51225</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-10T14:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155969#M51226</link>
      <description>&lt;P&gt;But if you have specific application named in your rule with application-default it goes my the specific applications and is not based on the services setting. So the change is only in regard to the services. I need to review my firewall and see how that will affect me when I upgrade&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what is going on in this rule for example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.PNG" style="width: 278px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9194i15B90921A2D9EF99/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule.PNG" alt="rule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 14:13:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155969#M51226</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-05-10T14:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155983#M51230</link>
      <description>&lt;P&gt;For your&amp;nbsp;example, upgrade to the&amp;nbsp;7.1.X release will not take any effect. Look for this rules:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.PNG" style="width: 719px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9199iF13F85C6DEBE632C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule.PNG" alt="rule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 15:19:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155983#M51230</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-10T15:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155990#M51232</link>
      <description>&lt;P&gt;So it will only apply to rules that have the service set to application-default&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 15:30:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/155990#M51232</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-05-10T15:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1 default behavior changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/156041#M51236</link>
      <description>&lt;P&gt;Behaviour change affects you only if you have rule where application is "any" AND service is "application-default"&lt;/P&gt;&lt;P&gt;It does not affect if you have set application/application filter/application group or if you have manually set service to some port number.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your example has no affect or change needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 20:01:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-default-behavior-changes/m-p/156041#M51236</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-10T20:01:22Z</dc:date>
    </item>
  </channel>
</rss>

