<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: service versus using an application for  Rule match in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236672#M67831</link>
    <description>&lt;P&gt;Can you please confirm if this is write for application&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When&amp;nbsp; we&amp;nbsp; use "application" in Rule that will allow the firewall to take action after enough packets are allowed&amp;nbsp; for App-ID identification regardless of the ports being used&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Oct 2018 13:55:10 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-10-23T13:55:10Z</dc:date>
    <item>
      <title>service versus using an application for  Rule match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236607#M67820</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to know if we use application instead of service in security policy&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we use service then that will enable the firewall to take immediate action with the first observed packet based on port number.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When&amp;nbsp; we&amp;nbsp; use "application" in Rule that will allow the firewall to take action after enough packets are allowed&amp;nbsp; for App-ID identification regardless of the ports being used ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 04:47:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236607#M67820</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-23T04:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: service versus using an application for  Rule match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236636#M67822</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideally both&lt;/P&gt;
&lt;P&gt;The services will be able to block/allow syn packets based on the destination port and applications will be able to identify if the packets flowing over port 80 are really web-browsing and not something else abusing the open port&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;setting the service to 'application-default' instead of a set of ports will enforce even tighter controls as a mixed rule ( ie. ftp, ssh, dns, ...) will ensure tcp&amp;nbsp;21 is only used by ftp&amp;nbsp;and not ssh which is allowed in the same rule&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 07:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236636#M67822</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-10-23T07:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: service versus using an application for  Rule match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236672#M67831</link>
      <description>&lt;P&gt;Can you please confirm if this is write for application&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When&amp;nbsp; we&amp;nbsp; use "application" in Rule that will allow the firewall to take action after enough packets are allowed&amp;nbsp; for App-ID identification regardless of the ports being used&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 13:55:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236672#M67831</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-23T13:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: service versus using an application for  Rule match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236713#M67835</link>
      <description>&lt;P&gt;Only if you set Service to any.&amp;nbsp; Then it will allow those specific applications through, regardless of which port the traffic is going through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you set Service to application-default, then it will only allow traffic through that matches the list of ports listed in the App-ID information for the application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you set a specific port/set of ports in the Service, then it will only allow traffic through that matches the application on the listed ports.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 17:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236713#M67835</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-10-23T17:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: service versus using an application for  Rule match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236751#M67842</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also remember that the PAN lets the first few packets through so it can analize them. It will then apply the polcies that match. I try and write my policies as strict as possible and use Application everywhere I can so I dont run into an application that likes to port hop or spoof itself as Reaper mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 19:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236751#M67842</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-23T19:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: service versus using an application for  Rule match</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236761#M67847</link>
      <description>&lt;P&gt;Many thanks Everyone.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 21:27:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-versus-using-an-application-for-rule-match/m-p/236761#M67847</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-23T21:27:50Z</dc:date>
    </item>
  </channel>
</rss>

