<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Persistent issue with APP-ID Reliability in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/persistent-issue-with-app-id-reliability/m-p/295586#M77855</link>
    <description>&lt;P&gt;Still no resolution on this I have opened ticket but no fixes yet&lt;/P&gt;</description>
    <pubDate>Thu, 31 Oct 2019 21:49:54 GMT</pubDate>
    <dc:creator>scottoliver</dc:creator>
    <dc:date>2019-10-31T21:49:54Z</dc:date>
    <item>
      <title>Persistent issue with APP-ID Reliability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/persistent-issue-with-app-id-reliability/m-p/295014#M77763</link>
      <description>&lt;P&gt;Hello all. I have had an issue with PANOS since 7.0 (Currently I am on 9.0.2-h2) where the application id feature is not reliable in security rules. I can add a rule and for example lets say I allow ssl to 10.1.1.1 from 10.2.1.1 no user restrictions and just add the ssl application and commit. Then I try to access https on 10.1.1.1 from 10.2.1.1 and the traffic will be allowed. Then an hour later I try again and this time it will drop. When I go into monitor. Below is legitimate traffic being dropped because the application is "not-applicable"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to resolve this what I have to do is clone the rule and place it below or above and remove the applications and set it to any then set service to select and choose 443. I have so many redundant rules because of this and I am sick of doing it. Does anyone else have this problem or is it just me?&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drops.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21968iE65682F4B3C07BC5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drops.png" alt="drops.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 17:25:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/persistent-issue-with-app-id-reliability/m-p/295014#M77763</guid>
      <dc:creator>scottoliver</dc:creator>
      <dc:date>2019-10-29T17:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Persistent issue with APP-ID Reliability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/persistent-issue-with-app-id-reliability/m-p/295179#M77772</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73655"&gt;@scottoliver&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you get any more information in the log details ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;Not-applicable usually means that the Palo Alto device has received data that will be discarded because the port or service that the traffic is coming in on is not allowed, or there is no rule or policy allowing that port or service:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClspCAC" target="_blank" rel="noopener"&gt;Not-applicable in Traffic Logs&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;Cheers !&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;-Kiwi.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 30 Oct 2019 12:56:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/persistent-issue-with-app-id-reliability/m-p/295179#M77772</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-10-30T12:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Persistent issue with APP-ID Reliability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/persistent-issue-with-app-id-reliability/m-p/295586#M77855</link>
      <description>&lt;P&gt;Still no resolution on this I have opened ticket but no fixes yet&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 21:49:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/persistent-issue-with-app-id-reliability/m-p/295586#M77855</guid>
      <dc:creator>scottoliver</dc:creator>
      <dc:date>2019-10-31T21:49:54Z</dc:date>
    </item>
  </channel>
</rss>

