<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Implicit Applications with cotp/ms-rdp in security policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/implicit-applications-with-cotp-ms-rdp-in-security-policies/m-p/294040#M77643</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112936"&gt;@MathewRD&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when the tcp handshake is initiated for any application the firewall will view all policies for an explicit allow. If none are available then it will check again for any implicit allows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i found these links helpful.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLLICA4" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLLICA4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV0CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV0CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2019 08:12:07 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-10-24T08:12:07Z</dc:date>
    <item>
      <title>Implicit Applications with cotp/ms-rdp in security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implicit-applications-with-cotp-ms-rdp-in-security-policies/m-p/293937#M77638</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Been testing some PA firewall functionality and noticed that ms-rdp has the implicit use of "cotp" defined, but the cotp application matches to a rule further down the policy list. When I review the logs, it looks like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAFWRDPCOTP.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21885iB7B90DC186DC1474/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PAFWRDPCOTP.PNG" alt="PAFWRDPCOTP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Am I misunderstanding having cotp as implicitly allowed by the ms-rdp application? Not sure why ms-rdp is allowed as part of the Test-RDP rule but then cotp drops down to a policy further in the list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could add the cotp application to the Test-RDP rule, but shouldn't Test-RDP be where cotp is getting caught already?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 19:17:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implicit-applications-with-cotp-ms-rdp-in-security-policies/m-p/293937#M77638</guid>
      <dc:creator>MathewRD</dc:creator>
      <dc:date>2019-10-23T19:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Implicit Applications with cotp/ms-rdp in security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implicit-applications-with-cotp-ms-rdp-in-security-policies/m-p/294040#M77643</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112936"&gt;@MathewRD&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when the tcp handshake is initiated for any application the firewall will view all policies for an explicit allow. If none are available then it will check again for any implicit allows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i found these links helpful.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLLICA4" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLLICA4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV0CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV0CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 08:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implicit-applications-with-cotp-ms-rdp-in-security-policies/m-p/294040#M77643</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-10-24T08:12:07Z</dc:date>
    </item>
  </channel>
</rss>

