<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic App-ID for general internet browsing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175399#M54968</link>
    <description>&lt;P&gt;This is a question for the Heavy App-ID users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you handle the rules for normal internet browsing? My users have access to most of the internet (except for a handfull of URL catagories) &amp;nbsp;I have been trying to figure out something using Application filters, but cant seem to quite hit on the right filters for an allow rule (seems like app-filters are more designed to be used in a deny rule). Are you denying traffic you dont want, then just allowing 80 and 443?&amp;nbsp;&lt;/P&gt;&lt;P&gt;My predicessor just put in a rule allowing the app of SSL and Web-browsing, but then promply followed it up by a rule allowing 80 and 443 that catches any Apps that are idenitifyed more more percicly then just "SSL" (IE google-base, Pandora, Citrix...)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So how do you guys handle this with APP-ID?&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2017 12:19:31 GMT</pubDate>
    <dc:creator>Kaje</dc:creator>
    <dc:date>2017-09-07T12:19:31Z</dc:date>
    <item>
      <title>App-ID for general internet browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175399#M54968</link>
      <description>&lt;P&gt;This is a question for the Heavy App-ID users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you handle the rules for normal internet browsing? My users have access to most of the internet (except for a handfull of URL catagories) &amp;nbsp;I have been trying to figure out something using Application filters, but cant seem to quite hit on the right filters for an allow rule (seems like app-filters are more designed to be used in a deny rule). Are you denying traffic you dont want, then just allowing 80 and 443?&amp;nbsp;&lt;/P&gt;&lt;P&gt;My predicessor just put in a rule allowing the app of SSL and Web-browsing, but then promply followed it up by a rule allowing 80 and 443 that catches any Apps that are idenitifyed more more percicly then just "SSL" (IE google-base, Pandora, Citrix...)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So how do you guys handle this with APP-ID?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 12:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175399#M54968</guid>
      <dc:creator>Kaje</dc:creator>
      <dc:date>2017-09-07T12:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID for general internet browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175410#M54972</link>
      <description>&lt;P&gt;I'd generally have 2 filters, one with 'good' and one with 'bad' apps and base everything on subcategories and technology that is accepted or should be blocked&lt;/P&gt;
&lt;P&gt;There may be overlap, so I'd place the bad apps above the good so unwanted apps that do match positive characteristics would still be blocked&lt;/P&gt;
&lt;P&gt;you can tune either as you go and the network evolves&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on top of App-ID there's also URL filtering and Threat Prevention to consider that can block unwanted applications, even if they match all the 'good' characteristcs but fall into an unwanted URL category or carry threats&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 12:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175410#M54972</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-09-07T12:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID for general internet browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175414#M54973</link>
      <description>&lt;P&gt;I have been messing around with the good and bad apps idea, but I am getting a lot of warnings&amp;nbsp;with the commits.. like "application _____ requires ____ to be allowed, but it is denied by....&lt;/P&gt;&lt;P&gt;Should this just be ignored?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 13:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175414#M54973</guid>
      <dc:creator>Kaje</dc:creator>
      <dc:date>2017-09-07T13:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID for general internet browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175416#M54974</link>
      <description>&lt;P&gt;If app x that requires app y is unimportant, you can ignore this warning, it will only break (or partially break) app x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A good feature request would be to have a toggle to automatically fix dependencies which could be very handy for the 'allow everything thats not explicitly bad' aproach&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 13:23:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175416#M54974</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-09-07T13:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID for general internet browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175466#M54979</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59867"&gt;@Kaje&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;I have been messing around with the good and bad apps idea, but I am getting a lot of warnings&amp;nbsp;with the commits.. like "application _____ requires ____ to be allowed, but it is denied by....&lt;/P&gt;&lt;P&gt;Should this just be ignored?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;You wouldn't like our warning list when we do a commit. It is HUGE and slightly annoying. As reaper started it would be nice to be able to toggle those off.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 16:05:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175466#M54979</guid>
      <dc:creator>Wald</dc:creator>
      <dc:date>2017-09-07T16:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID for general internet browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175469#M54981</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have always believed in the DENY ALL allow by exception. With that at the bottom of my policies I have a DENY ALL rule that blocks anything that was not allowed above it. While it does cause a bit more policies and TLC it better controls what traffic is allowed in/out/sideways etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also Applications become more apparent when you have SSL decryption enabled. For example we have to now allow web-browsing over port 443 since its 'default' port is 80.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So first I allow/block by URL categories, then I look at specific applications. i.e. there is no need to block the applications that allow file transfer if I block 'Online Storage and Backup' via URL, I don’t need to worry about all the applications that are used for this such as DropBox.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After this the Applications become less relevant until SSL decryption comes into play. Also at the top of my policies I do have Application Blocks using filters for the following: peer-to-peer, instant-messaging, and gaming.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 16:46:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175469#M54981</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-09-07T16:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID for general internet browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175617#M55019</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;are you able to show some screen shots to get an visual on your setup ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 11:49:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175617#M55019</guid>
      <dc:creator>AlexG</dc:creator>
      <dc:date>2017-09-08T11:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID for general internet browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175645#M55022</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42855"&gt;@AlexG&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is there a particular area of the setup you would like a screen shot from? I think i mentioned a few areas and want to make sure I provide you with the correct ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 13:28:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-for-general-internet-browsing/m-p/175645#M55022</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-09-08T13:28:46Z</dc:date>
    </item>
  </channel>
</rss>

