<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App-ID Mismatch for symantec-endpoint-manager in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185230#M56694</link>
    <description>&lt;P&gt;If there is an application default configured as a service on the Security Policy that allows symantec-endpoint-manager traffic, the Palo Alto firewall will deny web browsing traffic on destination port 8014.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two possible resolutions:&lt;/P&gt;&lt;P&gt;1- Allow any service in the Security Policy.&lt;/P&gt;&lt;P&gt;2- Allow web browsing traffic on destination port 8014.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for more details kindly find below URL:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Symantec-Endpoint-Protection-Manager-SEPM-Uses-Web-Browsing/ta-p/53224" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Symantec-Endpoint-Protection-Manager-SEPM-Uses-Web-Browsing/ta-p/53224&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2017 19:29:34 GMT</pubDate>
    <dc:creator>Feldiasti</dc:creator>
    <dc:date>2017-11-02T19:29:34Z</dc:date>
    <item>
      <title>App-ID Mismatch for symantec-endpoint-manager</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/184984#M56660</link>
      <description>&lt;P&gt;Is there any experience with 'symantec-endpoint-manager' over tcp/8014 being mis-identified as web-browsing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a 5260 firewall in a datacenter environment, with hosts that need to access a Symantec-Endpoint-Server for AV updates.&amp;nbsp; Clients access the server on port tcp/8014.&amp;nbsp; Tha pport is associated with app-id 'symantec-endpoint-manager'&amp;nbsp;per the&amp;nbsp;app-id with SSL and web-browsing dependencies.&amp;nbsp; A policy rule was created for the client to server communication with the three app-id's using the 'application default' ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the clients attempt to access the server, they are blocked by the inter-zone rule, with tcp/8014 identified as 'web browsing'.&amp;nbsp; At this point an application override has been created allowing tcp/8014, ideally we'd like to use the built-in rule to permit the traffic through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any input that can be provided by the community would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2017 19:31:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/184984#M56660</guid>
      <dc:creator>chrislss</dc:creator>
      <dc:date>2017-11-01T19:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID Mismatch for symantec-endpoint-manager</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185086#M56670</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="UserName lia-user-name lia-user-rank-L0-Member"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71080" target="_self"&gt;&lt;SPAN class=""&gt;chrislss,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L0-Member"&gt;&lt;SPAN class=""&gt;which version of PAN-OS you'r using in PA 5260 firewall&amp;nbsp; ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 08:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185086#M56670</guid>
      <dc:creator>Feldiasti</dc:creator>
      <dc:date>2017-11-02T08:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID Mismatch for symantec-endpoint-manager</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185226#M56692</link>
      <description>&lt;P&gt;The latest release, 8.0.5, is being used.&amp;nbsp; App/Threat update release is 745-4296 (10/24/17).&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 18:57:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185226#M56692</guid>
      <dc:creator>chrislss</dc:creator>
      <dc:date>2017-11-02T18:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID Mismatch for symantec-endpoint-manager</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185230#M56694</link>
      <description>&lt;P&gt;If there is an application default configured as a service on the Security Policy that allows symantec-endpoint-manager traffic, the Palo Alto firewall will deny web browsing traffic on destination port 8014.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two possible resolutions:&lt;/P&gt;&lt;P&gt;1- Allow any service in the Security Policy.&lt;/P&gt;&lt;P&gt;2- Allow web browsing traffic on destination port 8014.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for more details kindly find below URL:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Symantec-Endpoint-Protection-Manager-SEPM-Uses-Web-Browsing/ta-p/53224" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Symantec-Endpoint-Protection-Manager-SEPM-Uses-Web-Browsing/ta-p/53224&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 19:29:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185230#M56694</guid>
      <dc:creator>Feldiasti</dc:creator>
      <dc:date>2017-11-02T19:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID Mismatch for symantec-endpoint-manager</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185234#M56697</link>
      <description>&lt;P&gt;Thank you!&amp;nbsp; I have to say i don't like the solution, but that definitely explains the issue.&amp;nbsp; Appreciate the reference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 19:49:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-mismatch-for-symantec-endpoint-manager/m-p/185234#M56697</guid>
      <dc:creator>chrislss</dc:creator>
      <dc:date>2017-11-02T19:49:32Z</dc:date>
    </item>
  </channel>
</rss>

