<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to allow service for Ping application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285465#M76431</link>
    <description>&lt;P&gt;Hi Vince&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, In security rule I have allowed the application Ping , SSL, FTP and service as Application-default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the unwanted ports are hit the server without allowing the mentioned port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mohammed&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2019 09:22:46 GMT</pubDate>
    <dc:creator>MohammedAsik</dc:creator>
    <dc:date>2019-08-28T09:22:46Z</dc:date>
    <item>
      <title>Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285213#M76394</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured the one Destination NAT policy. My requirement is Ping the NAT IP (Public IP) from the external network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured one security policy with application as 'ping' and service as 'any'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the above configuration, I can able to ping the Public IP from the external network. But I want to allow the specific service for Ping application.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note : If I configured the service as "any or application-default", I can able to ping from the external network. If I mention particular service, I couldn't able to ping from the external network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, What is the service need to allow only for PIng application?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you need any further information, please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mohammed Asik&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 07:35:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285213#M76394</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2019-08-27T07:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285270#M76399</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Ping is neither TCP nor UDP, it's protocol 1 then I think you are unable to configure your own service.&lt;/P&gt;&lt;P&gt;In some fw you can find port 0.&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 12:21:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285270#M76399</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2019-08-27T12:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285350#M76419</link>
      <description>&lt;P&gt;The correct way to enable all applications, is to use the service of "application-default".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So change from service of "any" to "application-default"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 18:56:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285350#M76419</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-08-27T18:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285461#M76427</link>
      <description>&lt;P&gt;Hi Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had already configured as application default and I could able to ping from external network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the issue is, we are receiving the lot of unwanted ports hit the server. Due to this, Server load become high. So that only we want to mention the particular the ports in service.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitor.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21186iA795398B0E5B3F6A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="monitor.PNG" alt="monitor.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to block the unwanted port hit from firewall itself which will not hit the server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you suggest me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mohammed Asik&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 07:02:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285461#M76427</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2019-08-28T07:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285462#M76428</link>
      <description>&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seem you are on public IP range on both your wan and your DMZ. then if you just want to allowed ping. You should only have security rule like&lt;/P&gt;&lt;P&gt;from zone: WAN1-TATA&amp;nbsp;&lt;/P&gt;&lt;P&gt;To zone DMZ-1&lt;/P&gt;&lt;P&gt;To IP 203.196.171.56&lt;/P&gt;&lt;P&gt;Application: ping&amp;nbsp;&lt;/P&gt;&lt;P&gt;Service: Application default&lt;/P&gt;&lt;P&gt;Action: Allow&lt;/P&gt;&lt;P&gt;Your Internet-DMZServers rule should be TO LARGE &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Incomplete mean, syn arrive to your server and your server never answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 07:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285462#M76428</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2019-08-28T07:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285463#M76429</link>
      <description>&lt;P&gt;Hi Vince&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Incomplete mean, syn arrive to your server and your server never answer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes you're correct, the syn arrived to the server. My requirement is syn should not reach the server, it should block from firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can we achieve it ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mohammed Asik&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 08:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285463#M76429</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2019-08-28T08:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285464#M76430</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No reason for syn on port TCP/445 to arrive on your server if you don't want it.&lt;/P&gt;&lt;P&gt;But it seem your security rule allow it.&lt;/P&gt;&lt;P&gt;what your security rule look like ??&lt;/P&gt;&lt;P&gt;Allow only app on application-default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 08:26:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285464#M76430</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2019-08-28T08:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285465#M76431</link>
      <description>&lt;P&gt;Hi Vince&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, In security rule I have allowed the application Ping , SSL, FTP and service as Application-default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the unwanted ports are hit the server without allowing the mentioned port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mohammed&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 09:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285465#M76431</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2019-08-28T09:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Need to allow service for Ping application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285466#M76432</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have to know that before beeing able to indifty a complete app, your firewall nedd to first allow session's first packet.&lt;/P&gt;&lt;P&gt;Mean allowing syn / syn-ack /ack + first apcket.&lt;/P&gt;&lt;P&gt;At the beginning session identification is based on 5-tuple (&lt;SPAN&gt;source zone, source IP subnet, destination zone, destination IP subnet, destination port). Mean, based on this criterim, session match first security rule which allow these packet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If your rule is on top, it can explain strange traffic in your log.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;look:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS9CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS9CAK&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Rgds&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;V.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 09:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-allow-service-for-ping-application/m-p/285466#M76432</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2019-08-28T09:38:10Z</dc:date>
    </item>
  </channel>
</rss>

