<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic application any and service application default in policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-any-and-service-application-default-in-policy/m-p/258909#M73428</link>
    <description>&lt;P&gt;I have a Internet policy that permits application "any" with service "application-default".&amp;nbsp; I just discovered that we can no longer use Ookla Speedtest since turning on the "application-default" service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else experienced this and could you share how you resolved it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2019 17:02:20 GMT</pubDate>
    <dc:creator>ChrisBrun</dc:creator>
    <dc:date>2019-04-26T17:02:20Z</dc:date>
    <item>
      <title>application any and service application default in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-any-and-service-application-default-in-policy/m-p/258909#M73428</link>
      <description>&lt;P&gt;I have a Internet policy that permits application "any" with service "application-default".&amp;nbsp; I just discovered that we can no longer use Ookla Speedtest since turning on the "application-default" service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else experienced this and could you share how you resolved it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 17:02:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-any-and-service-application-default-in-policy/m-p/258909#M73428</guid>
      <dc:creator>ChrisBrun</dc:creator>
      <dc:date>2019-04-26T17:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: application any and service application default in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-any-and-service-application-default-in-policy/m-p/258926#M73436</link>
      <description>&lt;P&gt;As far as I know this speedtest uses TLS connections on port 8080. As the default port for the App ssl is 443 the firewall no longer allows these ssl connections from speedtest on port 8080.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To solve this issue you would have to create a new security policy that allows ssl on port 8080 and depending on your needs restrict it to specific IPs of servers that are used for the speedtest.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 20:47:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-any-and-service-application-default-in-policy/m-p/258926#M73436</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-26T20:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: application any and service application default in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-any-and-service-application-default-in-policy/m-p/258930#M73439</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95544"&gt;@ChrisBrun&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Aside from what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp; already mentioned; I'm assuming that you aren't doing outbound SSL-Decryption? If you were utilizing decryption a lot of additional app-ids will be identified properly and you can utilize your above policy for the majority of things. For example, what you mention would have fallen under the 'speedtest' app-id and been allowed, as long as decryption was enabled.&lt;/P&gt;&lt;P&gt;If you aren't utilizing SSL-Decryption on your outbound traffic app-id is only able to trigger off of what it can actually see in the traffic flow, making it essentially "best effort" identification.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Apr 2019 04:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-any-and-service-application-default-in-policy/m-p/258930#M73439</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-27T04:30:55Z</dc:date>
    </item>
  </channel>
</rss>

