<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does traffic log show Application for a rule that uses a Service? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160055#M52205</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;Every once in a while I can be a post ninja, but you usually beat me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2017 20:13:52 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2017-06-07T20:13:52Z</dc:date>
    <item>
      <title>Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160036#M52200</link>
      <description>&lt;P&gt;Hello folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am doing some testing (studying) on using Applications vs Services and have a question about the traffic log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why does the traffic log identify the traffic and rule to an Application when the rules are setup as Service?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My rules are setup as Service.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwapps.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9572i8394FE89958570E6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fwapps.jpg" alt="fwapps.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic log identifies them as Applications.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwapps3.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9573i85E6391333C7B3E4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fwapps3.jpg" alt="fwapps3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it because Applications are set to any?&lt;/P&gt;&lt;P&gt;I assuming that even though the Traffic log identifies an application, the traffic is not inspected as so (Layer 7)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 18:48:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160036#M52200</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-06-07T18:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160046#M52201</link>
      <description>&lt;P&gt;Layer 7 inspection happens on all sessions to a degree. An exception would be if you created an &lt;EM&gt;application override&amp;nbsp;&lt;/EM&gt;policy that would prevent it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your rules are port-based, but App-ID is still functioning. The application won't be taken into account when processing the rules, and with your profiles set to&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;none&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp;it will not be doing any threat scanning on the traffic hitting those rules, but App-ID is still active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 19:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160046#M52201</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-06-07T19:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160049#M52202</link>
      <description>&lt;P&gt;Palo does APP-ID and it based on the&amp;nbsp;traffic which is passing through. If you specify app as "any" and the&amp;nbsp;services as http or RDP in the security policy, palo&amp;nbsp;will scan all traffic that is matching this policy. Based on the&amp;nbsp;allowed port (services) it will identify application using app-id future (based on signature, port number etc). So Palo always does L7 inspection unless you do app-override, then it is only up to L4 (TCP/UDP port numbers).&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 19:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160049#M52202</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-07T19:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160050#M52203</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203"&gt;@gwesson&lt;/a&gt;&amp;nbsp;took me a bit longer to finish my post &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 20:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160050#M52203</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-07T20:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160055#M52205</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;Every once in a while I can be a post ninja, but you usually beat me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 20:13:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160055#M52205</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-06-07T20:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160056#M52206</link>
      <description>&lt;P&gt;Recently spending too much time next to the&amp;nbsp;pc.&amp;nbsp;Not good &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 20:21:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160056#M52206</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-07T20:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160072#M52209</link>
      <description>&lt;P&gt;Thank guys!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what if the traffic does not match an application in the database (when set to any)?&lt;/P&gt;&lt;P&gt;Does it just take the service port route and then skip Layer 7 inspection and stay at Layer 4?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 21:14:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160072#M52209</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-06-07T21:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160086#M52217</link>
      <description>&lt;P&gt;Nope, every initial packet will get Layer 7 inspection. It makes sense if you know the flow - if it has enough information to know it doesn't match any app, then it's already done the L7 inspection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If no app is matched, you'll see the app listed as "unknown-tcp" or "unknown-udp" depending on the underlying protocol. That is fairly rare though, as the app-id database is pretty expansive.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 22:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160086#M52217</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-06-07T22:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why does traffic log show Application for a rule that uses a Service?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160464#M52304</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 21:49:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-traffic-log-show-application-for-a-rule-that-uses-a/m-p/160464#M52304</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-06-09T21:49:11Z</dc:date>
    </item>
  </channel>
</rss>

