<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application vs Service in PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-service-in-pa/m-p/222320#M63939</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90544"&gt;@nsrini1991&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you set the service to 'any' the firewall continues to inspect traffic at the application layer, but this will allow ssl and web-browsing really on ANY port.&lt;/P&gt;&lt;P&gt;Almost all applications have a default port assigned, but this will only be enforced if you configure 'application-default' as service. This also means you cannot really filter for ports just with applications in your policy. The service column is also required to achieve the required result. (Except if you really want to allow web-browsing/ssl (or others) on ANY port, then of course ANY as service is the appropriate decision)&lt;/P&gt;</description>
    <pubDate>Sun, 15 Jul 2018 07:29:17 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-07-15T07:29:17Z</dc:date>
    <item>
      <title>Application vs Service in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-service-in-pa/m-p/222311#M63936</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I've query in Application vs Service columns. As we all know the Palo Alto preferred method is to use Application column (SSL, Web-browsing) and refer to 'Application default' in Service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My query is, if we mark 'ANY' in Service column and filter the ports in Application column (SSL, Web-browsing)&amp;nbsp; will PA firewall stop further processing and allow the traffic by looking&amp;nbsp;@L4&amp;nbsp;or will the inspection be continued for application layer. Please assist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA1.JPG" style="width: 272px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15914i18CF5B9B366AF012/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA1.JPG" alt="PA1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Srinivasan&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jul 2018 04:01:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-service-in-pa/m-p/222311#M63936</guid>
      <dc:creator>nsrini1991</dc:creator>
      <dc:date>2018-07-15T04:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Service in PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-service-in-pa/m-p/222320#M63939</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90544"&gt;@nsrini1991&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you set the service to 'any' the firewall continues to inspect traffic at the application layer, but this will allow ssl and web-browsing really on ANY port.&lt;/P&gt;&lt;P&gt;Almost all applications have a default port assigned, but this will only be enforced if you configure 'application-default' as service. This also means you cannot really filter for ports just with applications in your policy. The service column is also required to achieve the required result. (Except if you really want to allow web-browsing/ssl (or others) on ANY port, then of course ANY as service is the appropriate decision)&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jul 2018 07:29:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-service-in-pa/m-p/222320#M63939</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-15T07:29:17Z</dc:date>
    </item>
  </channel>
</rss>

