<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application Override in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/215093#M62450</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53640"&gt;@sidalpha2000&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you rephrase your question a little bit. Not sure what you are actually asking here.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 May 2018 20:14:10 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-05-22T20:14:10Z</dc:date>
    <item>
      <title>Application Override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/115572#M45422</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My client has an internal application that doesn't need App-ID (Layer 7) scans for better performance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I created the Application Override, under the "Protocols/Application" tab, there are 2 fields, one is Port and the other is Application.&amp;nbsp; I am very confused on these two fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port - Is it saying traffic utilizing my defined port (say TCP 21) will now bypass the App-ID engine? Or is it saying traffic will now be forced operate over TCP port 21? Or is it saying any traffic passing through as TCP 21 will now be classified as my pre-defined custom App (e.g. Say Client_FTP)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application - Is it saying traffic matching my pre-defined custom App (e.g. Say Client_FTP) will now bypass the App-ID engine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I look through many online documentation but all it says is put in port &amp;amp; application, without much explanation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciated if anyone can shed some light on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Hunt&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 03:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/115572#M45422</guid>
      <dc:creator>huntlee</dc:creator>
      <dc:date>2016-09-23T03:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Application Override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/115750#M45430</link>
      <description>&lt;P&gt;An app override policy is very similar to a standard firewall security policy. &amp;nbsp;With firewall policy, you define match criteria (source/dest/app/port/etc.) and if traffic matches the policy, then you get the resulting action (allow/deny). &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With application override, you define the match criteria and the firewall will OVERRIDE the detected application. &amp;nbsp;Go to Objects / Applications, and "Add" a new application. &amp;nbsp;You don't need to make layer-7 signatures for this new application, just give it a name and fill out the basics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, in your Application Override policy,&amp;nbsp;you'll define the match criteria:&lt;/P&gt;&lt;P&gt;&amp;nbsp;- source: internal systems&lt;/P&gt;&lt;P&gt;&amp;nbsp;- destination: server1&lt;/P&gt;&lt;P&gt;&amp;nbsp;- port: tcp21&lt;/P&gt;&lt;P&gt;&amp;nbsp;- APPLICATION: (use the new one you just defined)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You don't have to have all tcp/21 traffic overridden... just tcp21 traffic from your internal systems to the specific server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will also need to edit your security policy and permit traffic from internal systems to server1 using the newly-defined application on tcp/21. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 15:12:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/115750#M45430</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-09-23T15:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Application Override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/215065#M62439</link>
      <description>&lt;P&gt;Which event will happen if an administrator uses an Application Override Policy&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 19:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/215065#M62439</guid>
      <dc:creator>sidalpha2000</dc:creator>
      <dc:date>2018-05-22T19:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Application Override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/215093#M62450</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53640"&gt;@sidalpha2000&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you rephrase your question a little bit. Not sure what you are actually asking here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 20:14:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-override/m-p/215093#M62450</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-22T20:14:10Z</dc:date>
    </item>
  </channel>
</rss>

