<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy application question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-application-question/m-p/156173#M51263</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to configure "Application override".&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the only way, in palo, to diable L7 analysis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just keep in mind that by disabling L7, all security profile (Spyware / Antivirus ..) are disable on these flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;</description>
    <pubDate>Thu, 11 May 2017 07:58:54 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2017-05-11T07:58:54Z</dc:date>
    <item>
      <title>Policy application question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-application-question/m-p/156161#M51261</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I created an application&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TEST HTTPS tcp/443&lt;/P&gt;&lt;P&gt;TEST HTTP tcp/443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and a policy from any where to 10.10.10.10/24 application TEST HTTPS &amp;amp; TEST HTTP allow&lt;/P&gt;&lt;P&gt;and then deny everything else&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I go to my test box say 10.20.20.20/24 (different network), presume I can ping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I run&amp;nbsp;&lt;/P&gt;&lt;P&gt;telnet 10.10.10.10.443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it connects and i type GET /&lt;/P&gt;&lt;P&gt;This will fail, but the PA's say its applicaiton web-browsing - it doesn't use my application type.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can I make it use my applation type and stop it from looking at the packets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 06:54:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-application-question/m-p/156161#M51261</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-11T06:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Policy application question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-application-question/m-p/156173#M51263</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to configure "Application override".&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the only way, in palo, to diable L7 analysis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just keep in mind that by disabling L7, all security profile (Spyware / Antivirus ..) are disable on these flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 07:58:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-application-question/m-p/156173#M51263</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2017-05-11T07:58:54Z</dc:date>
    </item>
  </channel>
</rss>

