<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practice: Allowing a known application together with a custom service. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-allowing-a-known-application-together-with-a/m-p/261508#M74135</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113856"&gt;@jeroenverstraeten&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes you can combine applications with non-standard ports in one single rule :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Community-Blog/What-s-a-service-anyway/ba-p/155012" target="_blank" rel="noopener"&gt;What-s-a-service-anyway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Fri, 17 May 2019 13:28:08 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2019-05-17T13:28:08Z</dc:date>
    <item>
      <title>Best Practice: Allowing a known application together with a custom service.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-allowing-a-known-application-together-with-a/m-p/261496#M74133</link>
      <description>&lt;P&gt;Let's say we have 2 zones seperated by our PA firewall, Zone A and Zone B. Traffic between Zone A and Zone B is only allowed for some applications/services from dedicated devices in Zone A to dedicated devices in Zone B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a custom Service which uses TCP port 7777 named CustomService1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Device 1 in Zone A needs to access Device 2 in Zone B on our custom service AND by https. Is this possible in 1 rule?&lt;/P&gt;&lt;P&gt;Or do we need to configure this like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rule 1 = zone: Zone A | Address: Device 1 | zone: Zone B | Address: Device 2 | Application: web-browsing | Service: application defaults | action: Allow&lt;/P&gt;&lt;P&gt;rule 2 =&amp;nbsp;zone: Zone A | Address: Device 1 | zone: Zone B | Address: Device 2 | Application: any | Service: CustomService1 | action: Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 12:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-allowing-a-known-application-together-with-a/m-p/261496#M74133</guid>
      <dc:creator>jeroenverstraeten</dc:creator>
      <dc:date>2019-05-17T12:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice: Allowing a known application together with a custom service.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-allowing-a-known-application-together-with-a/m-p/261506#M74134</link>
      <description>&lt;P&gt;2 rules is going to be an OR.&amp;nbsp; If you want it to match an application &amp;amp; port, they need to be within the same rule.&amp;nbsp; Everything you match on in the same rule is an AND.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do those 2 seperate rules, it's going to allow ALL web browsing traffic on its default ports(80/443) as well as allow all traffic, web browsing or not, over tcp port 7777.&amp;nbsp; You could test the single rule requiring both app web-browsing/ssl &amp;amp; your custom service.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 13:14:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-allowing-a-known-application-together-with-a/m-p/261506#M74134</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2019-05-17T13:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice: Allowing a known application together with a custom service.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-allowing-a-known-application-together-with-a/m-p/261508#M74135</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113856"&gt;@jeroenverstraeten&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes you can combine applications with non-standard ports in one single rule :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Community-Blog/What-s-a-service-anyway/ba-p/155012" target="_blank" rel="noopener"&gt;What-s-a-service-anyway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 17 May 2019 13:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-allowing-a-known-application-together-with-a/m-p/261508#M74135</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-05-17T13:28:08Z</dc:date>
    </item>
  </channel>
</rss>

