<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AppID Rule with Service &amp;quot;any&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229362#M65932</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to now the risks of allowing an application with any services.&lt;/P&gt;&lt;P&gt;Below an example. Thank you in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="apponly.png" style="width: 795px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16416i2974F93A31C35CED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="apponly.png" alt="apponly.png" /&gt;&lt;/span&gt;Kind regards.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2018 10:08:33 GMT</pubDate>
    <dc:creator>wassim.bejaoui</dc:creator>
    <dc:date>2018-09-04T10:08:33Z</dc:date>
    <item>
      <title>AppID Rule with Service "any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229362#M65932</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to now the risks of allowing an application with any services.&lt;/P&gt;&lt;P&gt;Below an example. Thank you in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="apponly.png" style="width: 795px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16416i2974F93A31C35CED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="apponly.png" alt="apponly.png" /&gt;&lt;/span&gt;Kind regards.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 10:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229362#M65932</guid>
      <dc:creator>wassim.bejaoui</dc:creator>
      <dc:date>2018-09-04T10:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: AppID Rule with Service "any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229379#M65937</link>
      <description>&lt;P&gt;The 'risk' is low since you do filter on application and have security profiles in place&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be recommended and best practice to use "application-default" instead of "any" in most cases, because it is highly unusual and maybe even suspicious for any application to be detected on a different port than their default (why would DNS be transmitted over any other port than 53?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;applications using a different port are either badly configured (and do you want to allowed badly configured services to pass through) or being used for reconnaissance or exfiltration&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 11:57:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229379#M65937</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-09-04T11:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: AppID Rule with Service "any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229394#M65949</link>
      <description>&lt;P&gt;Hello, Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thank you for your quick response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you give me a real use case of exfiltration or&amp;nbsp;&lt;SPAN&gt;reconnaissance&lt;/SPAN&gt; in this type of rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 14:33:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229394#M65949</guid>
      <dc:creator>wassim.bejaoui</dc:creator>
      <dc:date>2018-09-04T14:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: AppID Rule with Service "any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229397#M65951</link>
      <description>&lt;P&gt;typically proxies and other protection mechanisms listen in on the default ports of applications, an attacker may do a port scan to find open ports or use legitimate connections to see if 'ports are open'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if a non-standard port is open, it is very likely the 'target' is not scanning properly for threats, so information can be sent out through that port to avoid detection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the fact that there's applications in your&amp;nbsp;policy will make this a lot harder, but why allow it in the first place&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 14:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/appid-rule-with-service-quot-any-quot/m-p/229397#M65951</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-09-04T14:54:45Z</dc:date>
    </item>
  </channel>
</rss>

