<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sophos Central firewall rules question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161541#M52545</link>
    <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Why would you chose a custom app-id over a URL filtering?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2017 08:09:58 GMT</pubDate>
    <dc:creator>njuttner</dc:creator>
    <dc:date>2017-06-16T08:09:58Z</dc:date>
    <item>
      <title>Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161389#M52512</link>
      <description>&lt;P&gt;My company is trying to implement&amp;nbsp; Sophos central throughout our network.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;All clients need the access listed in the article below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.sophos.com/kb/en-us/121936" target="_blank"&gt;https://community.sophos.com/kb/en-us/121936&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently Sophos central doesn't support the proxy solution we use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the best way to allow access through our Palo?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it url filtering or a custom application?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 16:45:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161389#M52512</guid>
      <dc:creator>njuttner</dc:creator>
      <dc:date>2017-06-15T16:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161411#M52521</link>
      <description>&lt;P&gt;Hi. Custom App could be difficult if SSL is used (looks like that they use SSL regarding of the required ports).&lt;/P&gt;&lt;P&gt;They dont use a lot URLs. I would setup a custom URL category and use it as a match criteria within my security rulebase with Application any and the requested ports. After a while&amp;nbsp;traffic is traversed that rule I would setup a report to get information about the used applications and at them to that rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers, Markus&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 18:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161411#M52521</guid>
      <dc:creator>markuskohlmeier</dc:creator>
      <dc:date>2017-06-15T18:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161412#M52522</link>
      <description>URL filtering is going to be the easiest to implement. If you can identify the proper information to correctly form a custom app-id I would always do that over URL Filtering.</description>
      <pubDate>Thu, 15 Jun 2017 18:18:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161412#M52522</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-15T18:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161541#M52545</link>
      <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Why would you chose a custom app-id over a URL filtering?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 08:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161541#M52545</guid>
      <dc:creator>njuttner</dc:creator>
      <dc:date>2017-06-16T08:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161546#M52548</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l think custom-app is more&amp;nbsp;secure. This way you definitely know that you are talking to the "right" server(s) (based on the customer&amp;nbsp;app signature and traffic logs). In you case because the&amp;nbsp;application is already identified you only need to allow ssl&amp;amp;web-browsing &amp;nbsp;between appropriate zones and filter&amp;nbsp;all traffic using your URL-Filtering profile. In the profile allow only your custom URL Sophos URLs. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 09:29:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161546#M52548</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-16T09:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161550#M52551</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9284"&gt;@njuttner&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Anytime you can use a custom app-id over a URL Filtering profile it's well advised that you create one and then secure it according to your needs. The thing with a URL Filtering profile is it's generally used in conjunction with [ ssl web-browsing ] and limiting it to a set of URLs. Obviously if you can create a custom app-id instead of utilizing either ssl or web-browsing app-ids it's encouragable that you do so as it gives you more access into your network activity and more granular control of what connections are actually allowed to be made.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 12:07:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161550#M52551</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-16T12:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161559#M52555</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I take it none of the Sophos apps in the PAN work for this? They can be found in the applipedia,&amp;nbsp;&lt;A href="https://applipedia.paloaltonetworks.com/" target="_blank"&gt;https://applipedia.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://applipedia.paloaltonetworks.com/#" target="_blank"&gt;sophos-live-protection&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;business-systems&lt;/TD&gt;&lt;TD&gt;software-update&lt;/TD&gt;&lt;TD&gt;&lt;IMG src="https://ip1.i.lithium.com/c42a7bfa4d2c3bb9921f68ac8aed0a686cd44d48/68747470733a2f2f6170706c6970656469612e70616c6f616c746f6e6574776f726b732e636f6d2f496d616765732f7269736b6c6576656c2f7269736b5f322e676966" border="0" alt="" title="2" /&gt;&lt;/TD&gt;&lt;TD&gt;client-server&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://applipedia.paloaltonetworks.com/#" target="_blank"&gt;sophos-rms&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;business-systems&lt;/TD&gt;&lt;TD&gt;management&lt;/TD&gt;&lt;TD&gt;&lt;IMG src="https://ip1.i.lithium.com/98e67812728e806dd49dd7e896f120fe9f0ba1f2/68747470733a2f2f6170706c6970656469612e70616c6f616c746f6e6574776f726b732e636f6d2f496d616765732f7269736b6c6576656c2f7269736b5f312e676966" border="0" alt="" title="1" /&gt;&lt;/TD&gt;&lt;TD&gt;client-server&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://applipedia.paloaltonetworks.com/#" target="_blank"&gt;sophos-update&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;business-systems&lt;/TD&gt;&lt;TD&gt;software-update&lt;/TD&gt;&lt;TD&gt;&lt;IMG src="https://ip1.i.lithium.com/98e67812728e806dd49dd7e896f120fe9f0ba1f2/68747470733a2f2f6170706c6970656469612e70616c6f616c746f6e6574776f726b732e636f6d2f496d616765732f7269736b6c6576656c2f7269736b5f312e676966" border="0" alt="" title="1" /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;client-server&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont use this product so I dont know.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 12:53:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161559#M52555</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-06-16T12:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161896#M52615</link>
      <description>&lt;P&gt;Hi Otakar,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The issue we have isn't that the apps aren't recognised. The issue we have is that currently Sophos Central (Cloud) isn't proxy aware so we'd have to allow all traffic from our subnet to the internet for those applications and their dependencies. That's something we'd prefer not to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 08:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/161896#M52615</guid>
      <dc:creator>njuttner</dc:creator>
      <dc:date>2017-06-19T08:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Central firewall rules question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/162016#M52641</link>
      <description>&lt;P&gt;Hello Nick,&lt;/P&gt;&lt;P&gt;I'm right there with you on that. However there are things you will not be able to decrypt due to many differnt issues. One good example of this is PAN updates, they cannot be decrypted. What we did is exclude that particular URL/IP address range and made the rule as specific as possible., i.e. source destination, applicayion, port, etc. We just created exclusions and called them 'trusted' end points off network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 17:03:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-central-firewall-rules-question/m-p/162016#M52641</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-06-19T17:03:47Z</dc:date>
    </item>
  </channel>
</rss>

