<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic App-ID Dependencies and Security Rule Order in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-dependencies-and-security-rule-order/m-p/210603#M61505</link>
    <description>&lt;P&gt;Which one of the following is the correct way to configure app-id and security rules? (Bonus points for why.)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa-rule-question.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14776i1BEE480264A9F161/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa-rule-question.png" alt="pa-rule-question.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Apr 2018 22:18:40 GMT</pubDate>
    <dc:creator>PUSDAlexK</dc:creator>
    <dc:date>2018-04-17T22:18:40Z</dc:date>
    <item>
      <title>App-ID Dependencies and Security Rule Order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-dependencies-and-security-rule-order/m-p/210603#M61505</link>
      <description>&lt;P&gt;Which one of the following is the correct way to configure app-id and security rules? (Bonus points for why.)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa-rule-question.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14776i1BEE480264A9F161/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa-rule-question.png" alt="pa-rule-question.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 22:18:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-dependencies-and-security-rule-order/m-p/210603#M61505</guid>
      <dc:creator>PUSDAlexK</dc:creator>
      <dc:date>2018-04-17T22:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID Dependencies and Security Rule Order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-dependencies-and-security-rule-order/m-p/210784#M61538</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87839"&gt;@PUSDAlexK&lt;/a&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;**I answered this question under the assumption that you are not running SSL-Decryption**&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) This would work; as when the firewall identifies 'netflix' as the app-id it will rescan the Security rulebase to see if you have a policy matching 'netflix'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) You would be blocking way too much in this policy, not just netflix.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Same thing as 2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So things to note here:&lt;/P&gt;&lt;P&gt;- You can block netflix by using a URL Filtering profile on the 'test allow' rule that simply includes 'netflix.com', '*.nflxvideo.net', and *.netflix.com' in the 'Block List'.&lt;/P&gt;&lt;P&gt;- When you are looking to block a specific app-id you don't necissarly have to include all application dependencies. This may cause commit warnings which can be annoying, but you can easily ignore them or eliminate them if you are willing to put some work in.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- ONly block the app-ids that you actually want to block access to. So in 2&amp;nbsp; as you originally noted this would have blocked all of your http-audio, http-video, and web-browsing. In option 3 you would still be blocking everything as you would be in 2, except web-browsing as all of that traffic would have already been allowed by the rule above it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 16:05:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-dependencies-and-security-rule-order/m-p/210784#M61538</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-18T16:05:24Z</dc:date>
    </item>
  </channel>
</rss>

