<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default Application ID change in 8.0? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251028#M71381</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48237"&gt;@DPoppleton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Actually FQDN might explain things. What version did you actually upgrade this to? Throughout 8.0 there are a number of times where FQDN objects didn't work as expected.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Feb 2019 21:24:00 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-02-22T21:24:00Z</dc:date>
    <item>
      <title>Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250901#M71349</link>
      <description>&lt;P&gt;We are migrating from some 200's running 7.1.x code to 220's running 8.0.x code. We had a rule that was working fine, allowing any traffic from a server to another server. We didn't define any apps or tcp ports. We have that rule in the new firewall, but it is now being blocked as "unknown-tcp".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We added a rule allowing any traffic between the servers over the port they use. It still is blocking it as unknown-tcp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why did this work in 7.1 but not in 8.0? I've gone through the release notes and there is nothing about application ID changes that would effect this. Is an application override the only way to get this to work?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 13:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250901#M71349</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-22T13:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250932#M71358</link>
      <description>&lt;P&gt;Do you have "application-default" as Service?&lt;/P&gt;&lt;P&gt;Change it to "any" and test.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:01:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250932#M71358</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-02-22T16:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250944#M71359</link>
      <description>&lt;P&gt;Application&amp;nbsp;and Service are both set to any. And it is the first rule, as this is a very important connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250944#M71359</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-22T16:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250945#M71360</link>
      <description>&lt;P&gt;Can you show screenshot of the rule and screenshot of Monitor &amp;gt; Logs &amp;gt; Traffic where this traffic is blocked?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250945#M71360</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-02-22T16:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250949#M71362</link>
      <description>&lt;P&gt;The rule that is the deny rule is the last rule, catch all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Deny.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18831i1683F97DA7897A8F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Deny.PNG" alt="Deny.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250949#M71362</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-22T16:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250979#M71367</link>
      <description>&lt;P&gt;Can you also share top rule that should permit this traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 18:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/250979#M71367</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-02-22T18:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251000#M71372</link>
      <description>&lt;P&gt;It's a pretty simple rule, and worked on 7.1:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18846i7D412FD61F4BB820/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Rule.PNG" alt="Rule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 19:25:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251000#M71372</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-22T19:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251001#M71373</link>
      <description>&lt;P&gt;So it stopped working after upgrade?&lt;/P&gt;&lt;P&gt;Can you create new rule and instead of using address groups just add single ip to source and destination.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those that you hid in your first screenshot.&lt;/P&gt;&lt;P&gt;To be sure that this source and destination are included in those groups.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 19:30:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251001#M71373</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-02-22T19:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251003#M71374</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48237"&gt;@DPoppleton&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a setting where you can disallow any unknown-tcp or unknown-udp traffic; let me see if I can find it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;edit: I can't seem to find it with a quick glance but I'm fairly certain that was/is a thing. In the meantime you could utilize an application-override policy to classify the traffic as another application, or a custom application, and it should match your existing rule.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 20:00:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251003#M71374</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-22T20:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251004#M71375</link>
      <description>&lt;P&gt;We tried that already. A rule with just the server as the source, and the object it was trying to go to as the destination, any application with a service of tcp/50000. Still fell through to the deny rule at the end as unknown-tcp.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 20:02:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251004#M71375</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-22T20:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251005#M71376</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48237"&gt;@DPoppleton&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;That would lead me to possibly start looking at the address objects that were passed in and seeing if they somehow are the problem. Try testing with a policy that actually specifies the IP of one of the servers and see if you see the same behavior.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 20:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251005#M71376</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-22T20:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251009#M71378</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;the destination is a FQDN. I verified that the name resolved in the firewall by using "request system fqdn show" but I was wondering as well if there is failure&amp;nbsp;with that somewhere.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 20:15:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251009#M71378</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-22T20:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251026#M71380</link>
      <description>&lt;P&gt;&amp;nbsp;We have another test window on Monday... I'll let you know how it goes.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 21:12:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251026#M71380</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-22T21:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251028#M71381</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48237"&gt;@DPoppleton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Actually FQDN might explain things. What version did you actually upgrade this to? Throughout 8.0 there are a number of times where FQDN objects didn't work as expected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 21:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251028#M71381</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-22T21:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251037#M71383</link>
      <description>&lt;P&gt;It's 8.0.15. I was kind of hoping all the bugs would have been found by now.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 21:37:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251037#M71383</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-22T21:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Default Application ID change in 8.0?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251185#M71430</link>
      <description>&lt;P&gt;We changed the target from an FQDN to an IP address and it is working. So it looks like another bug with FQDN. We're not going to celebrate yet as we will give it a few days to ensure it stays working, but it is looking good.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 17:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-application-id-change-in-8-0/m-p/251185#M71430</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-02-25T17:03:20Z</dc:date>
    </item>
  </channel>
</rss>

