<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't Create Rule for National Bindery Library App in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8412#M6206</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I submitted this to applpedia just after your post. I never even received a confirmation that it had been received. Should I have?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 May 2011 20:26:09 GMT</pubDate>
    <dc:creator>david_scott</dc:creator>
    <dc:date>2011-05-17T20:26:09Z</dc:date>
    <item>
      <title>Can't Create Rule for National Bindery Library App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8410#M6204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;I work in a University, and recently our library began to use - or try to use - an app called "Able" from &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://able.nationalbindery.com"&gt;http://able.nationalbindery.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're behind a PA 2050 running 3.1.5 firmware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The site uses an embedded Java app to communicate with a remote server. From what I can tell, the client initiates a session to dst port 80, then the server responds and all future communication happens across remote tcp port 9000 (and whatever random port the client chooses).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't seem to create a policy that will allow this traffic. I've created a policy from "Trust" to "Untrust" allowing "Service" tcp 80 and tcp 9000.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also added a policy from "Untrust" to "Trust", allowing port 9000. Nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any experiece with this app? I can provide a pcap if necessary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;David Scott&lt;/P&gt;&lt;P&gt;Freed-Hardeman University&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 May 2011 19:15:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8410#M6204</guid>
      <dc:creator>david_scott</dc:creator>
      <dc:date>2011-05-11T19:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Create Rule for National Bindery Library App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8411#M6205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@david.scott:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can submit an application request via the Applipedia section of our support website:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://ww2.paloaltonetworks.com/applipedia/"&gt;http://ww2.paloaltonetworks.com/applipedia/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;click the "tools" link and then the "submit an app" link&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A packet capture from the client PC is always helpful when creating new application signatures.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 May 2011 19:19:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8411#M6205</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-05-11T19:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Create Rule for National Bindery Library App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8412#M6206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I submitted this to applpedia just after your post. I never even received a confirmation that it had been received. Should I have?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 20:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8412#M6206</guid>
      <dc:creator>david_scott</dc:creator>
      <dc:date>2011-05-17T20:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Create Rule for National Bindery Library App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8413#M6207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe the tcp 9000 traffic is actually client-server, but with your PC acting as server and their webserver acting as client.&lt;/P&gt;&lt;P&gt;If that's the case, you need some sort of "secondary connections" mechanism.&lt;/P&gt;&lt;P&gt;Or, if there would be only one PC the application is used from, a NAT port forwarding...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 May 2011 10:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-create-rule-for-national-bindery-library-app/m-p/8413#M6207</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2011-05-18T10:13:53Z</dc:date>
    </item>
  </channel>
</rss>

