<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How Security Policy works with Combination of Application vs Services  ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-works-with-combination-of-application-vs/m-p/256174#M72678</link>
    <description>&lt;P&gt;Hi Experts ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have existing rule for "Syslog" application ,our current security polcy with App-id and services configured as below ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application - "Syslog" ( default application which allows&amp;nbsp;TCP 1468, &amp;nbsp;TCP 1514, TCP 6514, UDP 514 and UDP 1514 )&amp;nbsp;&lt;/P&gt;&lt;P&gt;Service&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; "application-default"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we have a requirement to additionally add TCP-514 and UDP-6514 to this rule .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question here is do I need to only add&amp;nbsp;TCP-514 and UDP-6514 under services instead of application-default and this means&amp;nbsp;&amp;nbsp;you only need to add the ports to the service group that are not covered under the default app port list .&amp;nbsp; or&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to add (TCP 1468, &amp;nbsp;TCP 1514, TCP 6514, UDP 514 and UDP 1514)&amp;nbsp; &amp;nbsp;+ additional 2 ports TCP-514 &amp;amp; UDP-6514 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How this will work . Can someone please explain me .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note : I don't want to allow "Any" port - We need more secure option for achieving the end goal by adding the&lt;/P&gt;&lt;P&gt;the required services in the Service field rather than using Any.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chethan&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2019 20:17:52 GMT</pubDate>
    <dc:creator>Karkerachethan</dc:creator>
    <dc:date>2019-04-04T20:17:52Z</dc:date>
    <item>
      <title>How Security Policy works with Combination of Application vs Services  ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-works-with-combination-of-application-vs/m-p/256174#M72678</link>
      <description>&lt;P&gt;Hi Experts ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have existing rule for "Syslog" application ,our current security polcy with App-id and services configured as below ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application - "Syslog" ( default application which allows&amp;nbsp;TCP 1468, &amp;nbsp;TCP 1514, TCP 6514, UDP 514 and UDP 1514 )&amp;nbsp;&lt;/P&gt;&lt;P&gt;Service&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; "application-default"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we have a requirement to additionally add TCP-514 and UDP-6514 to this rule .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question here is do I need to only add&amp;nbsp;TCP-514 and UDP-6514 under services instead of application-default and this means&amp;nbsp;&amp;nbsp;you only need to add the ports to the service group that are not covered under the default app port list .&amp;nbsp; or&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to add (TCP 1468, &amp;nbsp;TCP 1514, TCP 6514, UDP 514 and UDP 1514)&amp;nbsp; &amp;nbsp;+ additional 2 ports TCP-514 &amp;amp; UDP-6514 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How this will work . Can someone please explain me .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note : I don't want to allow "Any" port - We need more secure option for achieving the end goal by adding the&lt;/P&gt;&lt;P&gt;the required services in the Service field rather than using Any.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chethan&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 20:17:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-works-with-combination-of-application-vs/m-p/256174#M72678</guid>
      <dc:creator>Karkerachethan</dc:creator>
      <dc:date>2019-04-04T20:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: How Security Policy works with Combination of Application vs Services  ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-works-with-combination-of-application-vs/m-p/256212#M72686</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This can be accomplished two ways.&lt;/P&gt;&lt;P&gt;1. One policy that has the application syslog and you specify the ports/services&lt;/P&gt;&lt;P&gt;2. two policies first one is application syslog and default services/ports, and the second one would be application syslog with the ports that you need that are missing from the default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remember that the firewall reads policies top down then left to right. so everything needs to match prior to the firewall applying that policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a policy that is application syslog and default services, but you need tcp/514, this policy will NOT apply. If you have a policy application syslog and you specify port tcp/514, the firewall will only allow syslog identified traffic over port tcp/514.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 21:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-works-with-combination-of-application-vs/m-p/256212#M72686</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-04-04T21:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: How Security Policy works with Combination of Application vs Services  ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-works-with-combination-of-application-vs/m-p/256249#M72699</link>
      <description>&lt;P&gt;I want in one rule . I don't want to create 2 different rules . So I do i need to add all the service ports which are already there in Application Syslog + Additional ports TCP-514 and UDP-6514 .&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 06:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-works-with-combination-of-application-vs/m-p/256249#M72699</guid>
      <dc:creator>Karkerachethan</dc:creator>
      <dc:date>2019-04-05T06:55:11Z</dc:date>
    </item>
  </channel>
</rss>

