<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: commit status warning on rules that are working the way  I want them too in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208116#M60951</link>
    <description>&lt;P&gt;OK, we see this all the time. One thing to keep in mind is the application/traffic may work without the dependencies *but* some components of it may not work and you may not notice or the app may fall back onto something else if it fails one piece.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what we try to do and a lot of people forget they can do this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Setup your security policy and add the dependencies&lt;/P&gt;&lt;P&gt;* validate the commit does not have any dependenciy warnings&lt;/P&gt;&lt;P&gt;* Scope the policy down to specific destinations (if possible) or use a URL category in the policy, using a URL category will at least make it so users will not hit this policy for all web browsing and hopefully only hit it for the application/URL catgories specified&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for example we have exceptions to allow people to hit online file storage junk (box, dropbox,etc) so aside from the user having to be in the proper AD group for the exception the destination also has to be one related to the exception and/or the URL category has to match, otherwise they will hit the standard web traffic policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the web-browsing and ssl applications will be a pain no matter what (try locking down slack and have fun)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Mar 2018 18:57:26 GMT</pubDate>
    <dc:creator>hshawn</dc:creator>
    <dc:date>2018-03-29T18:57:26Z</dc:date>
    <item>
      <title>commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208061#M60929</link>
      <description>&lt;P&gt;I have a rule that has webex enabled but dones not have ssl enabled and i keep getting a warning on that rule when i commit that says "Applicaiton 'webex-desktop-sharing requires ssl be allowed? But I don't want to allow ssl, so how can I get rid of these warnings so i can tell when i have a legitimate commit warning?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 15:48:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208061#M60929</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-29T15:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208071#M60930</link>
      <description>&lt;P&gt;I hope there is a solution but I asume there isn't ... some applications simply have a dependency to others. So even if it works in most cases there might be some edge cases where the firewall first sees ssl and after some more packets thw app changes to webex. So in these cases it could be that it won't work with allowing only webex...&lt;/P&gt;&lt;P&gt;Hopefully there is a way, cause the commit warnings I have are growing and growing ...&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:09:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208071#M60930</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-29T16:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208072#M60931</link>
      <description>&lt;P&gt;ssl is a dependency of the webex desktop sharing application...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;according to this doc...&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-What-is-Application-Dependency/ta-p/54270" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-What-is-Application-Dependency/ta-p/54270&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it states...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;If you do not allow the application and its dependency through the Palo Alto Networks firewall, then the application will not work.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="padep2.png" style="width: 791px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14548iA3B3A271962AB7B8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="padep2.png" alt="padep2.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:09:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208072#M60931</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-29T16:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208074#M60933</link>
      <description>&lt;P&gt;sorry, answered after &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;...&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:10:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208074#M60933</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-29T16:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208076#M60934</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;thing is it does work and I would think it shouldn't , for instance this is in the commit warning&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Application 'google-plus-base' requires 'google-base' be allowed&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And this is what it says in the applicatiion info -&amp;nbsp;google-play standard ports 443,5227,80,tcp,udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I look in the traffic and unless I am reading this wrong it is work even though ssl is not allowed so to speak&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="google plus base.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14549i52FB71271688813A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="google plus base.PNG" alt="google plus base.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:27:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208076#M60934</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-29T16:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208077#M60935</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;@&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually I think it is working that is why I am surprised, look at my reply to remo&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:21:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208077#M60935</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-29T16:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208078#M60936</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I know it works, thats why I have endless commit warnings &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Exactly like your initial example. You only want to allow webex but not general ssl access to everywhere ...&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208078#M60936</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-29T16:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208079#M60937</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yeah and the impression from the commit warning is that it should not work without ssl but it does, because the ssl port 443 is allowed, from what I see&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208079#M60937</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-29T16:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208082#M60938</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I guess I want away to clean up my commit status errors without having to add ssl to a rule that I don't want ssl enabled on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208082#M60938</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-29T16:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208084#M60940</link>
      <description>&lt;P&gt;ok so having added the dependencies to the webex desktop sharing policy, the warnings have gone...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is this a problem, will it not only use these dependencies for webex desktop and nothing else...&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:54:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208084#M60940</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-29T16:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208091#M60941</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that giving it what it wants to make the commit status errors go away but I don't want ssl on those rules at all&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208091#M60941</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-29T16:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208092#M60942</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;No, if you add these dependencies then the firewall also allows these apps independently.&lt;/P&gt;&lt;P&gt;So ...&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Allowing just webex --&amp;gt; working solution but commit warning&lt;/LI&gt;&lt;LI&gt;Allowing webex with dependencies --&amp;gt; webex works but also general webaccess and the commit warning is gone&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or ...&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Secure solution --&amp;gt; commit warning&lt;/LI&gt;&lt;LI&gt;Insecure solution --&amp;gt; no commit warning&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 29 Mar 2018 17:08:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208092#M60942</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-29T17:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208096#M60943</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;. Sorry... its been a long day.... i feel so stupid.&lt;/P&gt;&lt;P&gt;i thougt i was adding the dependencies into a different section of the policy, not into the same app section of the policy as webex desktop...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i feel this will not be marked as a solution.....&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:09:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208096#M60943</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-29T18:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208109#M60947</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No problem Mick you always give it your best, this is just a weird situation&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:34:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208109#M60947</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-29T18:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208116#M60951</link>
      <description>&lt;P&gt;OK, we see this all the time. One thing to keep in mind is the application/traffic may work without the dependencies *but* some components of it may not work and you may not notice or the app may fall back onto something else if it fails one piece.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what we try to do and a lot of people forget they can do this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Setup your security policy and add the dependencies&lt;/P&gt;&lt;P&gt;* validate the commit does not have any dependenciy warnings&lt;/P&gt;&lt;P&gt;* Scope the policy down to specific destinations (if possible) or use a URL category in the policy, using a URL category will at least make it so users will not hit this policy for all web browsing and hopefully only hit it for the application/URL catgories specified&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for example we have exceptions to allow people to hit online file storage junk (box, dropbox,etc) so aside from the user having to be in the proper AD group for the exception the destination also has to be one related to the exception and/or the URL category has to match, otherwise they will hit the standard web traffic policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the web-browsing and ssl applications will be a pain no matter what (try locking down slack and have fun)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208116#M60951</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-03-29T18:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208117#M60952</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42784"&gt;@hshawn&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting information , we know what we do and don't want to allow and we have decided to not allow ssl, so you would think if you didn't allow a dependencies it should not work but.... when I look in the logs it works just fine and even though I havent allowed ssl or web -browsing I can see it using port 80 and port 443. My first thought is that either the application isn't defined enough or my rule is not.&amp;nbsp; I could fix it by adding the dependency to the rule or in this case ssl, but I don't want it allowed.&lt;/P&gt;&lt;P&gt;I have a specified source and destination zone, specific source IP, it confined to only two specific regions,&amp;nbsp; specific application s(set to application default)&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 19:11:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208117#M60952</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-29T19:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208443#M61008</link>
      <description>&lt;P&gt;Okay i am still tracking this for a solution and I got this today in the commit status but i clearing see google-play traffic in the traffic logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;commit status&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Application 'google-play' requires 'google-base' be allowed and i can clearly see spotified traffic in the traffic logs&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And I also have this in the commit status&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Application 'spotify' requires 'ssl' be allowed&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 02 Apr 2018 18:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208443#M61008</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-04-02T18:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208444#M61009</link>
      <description>&lt;P&gt;Sometimes App-ID can determine that the app is google-play without using the application dependencies, so you're able to see the app. An example is one where the client is sending the Client Hello with "play.google.com" in the server_name extension, so it's easy to tell.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But other times the user would have already been logged into google, and the check is against "accounts.google.com". Unless you're doing SSL decryption, you can't see the actual encrypted request to the play store. If you can't see that it's google play and you haven't allowed SSL anywhere in your security policy, there will be situations where a user is denied going to google play but other times it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The commit warning could probably be "application 'google-play' requires 'google-base' to be allowed&amp;nbsp;&lt;EM&gt;for reliable detection of 'google-play'&lt;/EM&gt;", but that may just be too wordy and may even generate more questions about what specific scenarios will cause it to be matched versus not. It's much simpler to state the dependency as a requirement, even if there are conditions that will sometimes allow for detection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 18:53:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208444#M61009</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-04-02T18:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208447#M61012</link>
      <description>&lt;P&gt;It's sometimes hard to actually lay out the application dependency simply due to the fact that some users utilize SSL-Decryption and others don't. There are quite a few apps that the dependency isn't as necissary when running SSL-Decryption, but it needs to be there for people who are not utilizing that feature.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 19:00:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208447#M61012</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-02T19:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: commit status warning on rules that are working the way  I want them too</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208449#M61013</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203"&gt;@gwesson&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So in other words it can be hit or miss, that doesn't sound good.&amp;nbsp; But my biggest issue is that i want to clean up the commit status message and I was thinking if I am not allowing it, via dependencies, it just shouldn't work&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 19:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-status-warning-on-rules-that-are-working-the-way-i-want/m-p/208449#M61013</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-04-02T19:06:26Z</dc:date>
    </item>
  </channel>
</rss>

