<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Application v default-Application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174957#M54884</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71257"&gt;@Light-Regions&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is recommended to use custom applications when creating app-overrides. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to use app-override on all your custom applications (unless you don't want layer-7 inspection).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By adding the port numbers for a custom application, you can create policy rules that use the application defaults rather than opening up additional ports on the firewall. This improves your security posture.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This getting started guide on custom applications and application override will probably help you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2017 15:26:37 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-09-05T15:26:37Z</dc:date>
    <item>
      <title>Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174951#M54880</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am planning to replace the services in my environment with custom applications. My question is this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(1) - Must I use application override to use custom application?&lt;/P&gt;&lt;P&gt;(2)- While using custom application, can I use default-application on the Service Column? Or should this column be set to Any since the default app is not in use&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 14:37:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174951#M54880</guid>
      <dc:creator>Light-Regions</dc:creator>
      <dc:date>2017-09-05T14:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174953#M54881</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A lot of a good article here as well as video training on youtube, but short answer on your questions below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(1) - Must I use application override to use custom application? - No, not necessarily if your application will be identified by signature&amp;nbsp;and parameters you specify.&lt;/P&gt;&lt;P&gt;(2)- While using custom application, can I use default-application on the Service Column? Or should this column be set to Any since the default app is not in use - "any" in service column means your app will be allowed on any port (PAN-OS 7.1.x and above), if "application-default" then your app is allowed only on standard/predefined ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 14:55:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174953#M54881</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-09-05T14:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174954#M54882</link>
      <description>&lt;P&gt;Thanks a&amp;nbsp;lot TranceforLife,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That was a quick turn around. I know that application-default is for standard/predefined ports?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do I set that service column when using my custom applications?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Syl&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 15:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174954#M54882</guid>
      <dc:creator>Light-Regions</dc:creator>
      <dc:date>2017-09-05T15:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174955#M54883</link>
      <description>&lt;P&gt;If your custom app will have a port number, then it is your choice. &amp;nbsp;As I said earlier "any" will allow your custom app on any port (not recommended), "application-default" will allow your app only on the defined in custom app port number or range.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-What-Does-Application-default-Under-Service-Mean/ta-p/54167" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-What-Does-Application-default-Under-Service-Mean/ta-p/54167&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do they mean?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This simply means all ports: 1-65535, TCP or UDP. The selected applications are allowed or denied on any protocol or port.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Select&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This means that you will have to specify exactly what TCP or UDP port that the application you want to allow or block is going to use. Choose an existing service or choose Service or Service Group to specify a new entry.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Application-Default&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Choosing this means that the selected applications are allowed or denied only on their default ports defined by Palo Alto Networks. This option is recommended for allow policies because it prevents applications from running on unusual ports and protocols, which if not intentional, can be a sign of undesired application behavior and usage.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 05 Sep 2017 15:09:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174955#M54883</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-09-05T15:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174957#M54884</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71257"&gt;@Light-Regions&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is recommended to use custom applications when creating app-overrides. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to use app-override on all your custom applications (unless you don't want layer-7 inspection).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By adding the port numbers for a custom application, you can create policy rules that use the application defaults rather than opening up additional ports on the firewall. This improves your security posture.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This getting started guide on custom applications and application override will probably help you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 15:26:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/174957#M54884</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-09-05T15:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/175100#M54907</link>
      <description>&lt;P&gt;Thanks very Much Kiwi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is a very clear answer with clear direction on what to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 07:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/175100#M54907</guid>
      <dc:creator>Light-Regions</dc:creator>
      <dc:date>2017-09-06T07:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/175101#M54908</link>
      <description>&lt;P&gt;Thank you TranceforLife,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I now understand it a lot clearer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very many thanks indeed!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 07:13:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/175101#M54908</guid>
      <dc:creator>Light-Regions</dc:creator>
      <dc:date>2017-09-06T07:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/331181#M83886</link>
      <description />
      <pubDate>Tue, 02 Jun 2020 19:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/331181#M83886</guid>
      <dc:creator>ccfalkner</dc:creator>
      <dc:date>2020-06-02T19:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application v default-Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/331182#M83887</link>
      <description>&lt;P&gt;To keep the security policy list clean, it would be great if I could create a custom application and just change/add my own default ports. This way I can just re-use the application anywhere, inside of perhaps one security policy with all applications for the zone.&amp;nbsp; I want full analysis of the packet, so application-override isn't appealing.&amp;nbsp; Once you start adding services, you either have to have an additional policy just for your app/custom service ports, or have to research all application-default ports for all applications you add to the policy, which is tedious and less secure.&amp;nbsp; Even with service groups, the complication creeps up with duplication of the policy to other areas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't done a deep dive on this since PanOs 7.x, but still in 9.1, I can create an application and leave the custom signature blank without an error, but my new custom application still doesn't get any hits. Let's just say I want to use web-browsing with ports 8070, 8080 and 8090 for any similar web server throughout my enterprise.&amp;nbsp; Is it possible to create a custom application for this, or any application? If not, I wish they would add that feature.&amp;nbsp; Seems so logical and clean.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 19:19:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-application-v-default-application/m-p/331182#M83887</guid>
      <dc:creator>ccfalkner</dc:creator>
      <dc:date>2020-06-02T19:19:50Z</dc:date>
    </item>
  </channel>
</rss>

