<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Basic Question on Apps vs Service Relationships in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/basic-question-on-apps-vs-service-relationships/m-p/10747#M7924</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have attached a PDF that shows screenshots of the same rule, in four different variations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to understand the relationships between using applications and traditional ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a server that has a static public IP NATed to the private internal IP.&lt;/P&gt;&lt;P&gt;I need telnet, FTP and web browsing allowed on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I originally setup the rule to be like # 3.&amp;nbsp; Using the default PA provided service group of service-http that does 80 and 8080 and applications FTP and Telnet.&amp;nbsp; None of the three services worked under this configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I modified the rule to look like # 1 and all three services worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I played with it more to see about how the relationships work between applications and services and came up with two additional variations.&amp;nbsp; # 2 and # 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# 2 works like # 1, all three applications work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# 4, FTP and Telnet do not work, but the website does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question to you all is what is this relationship doing?&amp;nbsp; Why does # 3 not allow any of the three services to work, yet # 4 allows the website to work but not ftp and telnet?&amp;nbsp; Can I mix and match applications and services in the same rule or do I need to break them apart? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This simple example is not a big deal but I have some servers that use known applications like FTP and MSSQL that I would like to switch over to use pure applications for them in the rule but they also have some proprietary ports that are unique to them that I will need to keep listed as services.&amp;nbsp; So before I start mucking with them I'd like to have a better understanding of how this is supposed to be working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any advice and guidance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Nov 2011 21:00:19 GMT</pubDate>
    <dc:creator>nathan_gilmore</dc:creator>
    <dc:date>2011-11-28T21:00:19Z</dc:date>
    <item>
      <title>Basic Question on Apps vs Service Relationships</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-question-on-apps-vs-service-relationships/m-p/10747#M7924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have attached a PDF that shows screenshots of the same rule, in four different variations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to understand the relationships between using applications and traditional ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a server that has a static public IP NATed to the private internal IP.&lt;/P&gt;&lt;P&gt;I need telnet, FTP and web browsing allowed on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I originally setup the rule to be like # 3.&amp;nbsp; Using the default PA provided service group of service-http that does 80 and 8080 and applications FTP and Telnet.&amp;nbsp; None of the three services worked under this configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I modified the rule to look like # 1 and all three services worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I played with it more to see about how the relationships work between applications and services and came up with two additional variations.&amp;nbsp; # 2 and # 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# 2 works like # 1, all three applications work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# 4, FTP and Telnet do not work, but the website does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question to you all is what is this relationship doing?&amp;nbsp; Why does # 3 not allow any of the three services to work, yet # 4 allows the website to work but not ftp and telnet?&amp;nbsp; Can I mix and match applications and services in the same rule or do I need to break them apart? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This simple example is not a big deal but I have some servers that use known applications like FTP and MSSQL that I would like to switch over to use pure applications for them in the rule but they also have some proprietary ports that are unique to them that I will need to keep listed as services.&amp;nbsp; So before I start mucking with them I'd like to have a better understanding of how this is supposed to be working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any advice and guidance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 21:00:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-question-on-apps-vs-service-relationships/m-p/10747#M7924</guid>
      <dc:creator>nathan_gilmore</dc:creator>
      <dc:date>2011-11-28T21:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Question on Apps vs Service Relationships</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-question-on-apps-vs-service-relationships/m-p/10748#M7925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I should have searched more before posting as I believe my questions were already answered in the following two posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿&lt;A href="https://live.paloaltonetworks.com/message/5821#5821"&gt;https://live.paloaltonetworks.com/message/5821#5821&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/3134#3134"&gt;https://live.paloaltonetworks.com/message/3134#3134&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If others have additional thoughts they want to add please post still.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 21:48:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-question-on-apps-vs-service-relationships/m-p/10748#M7925</guid>
      <dc:creator>nathan_gilmore</dc:creator>
      <dc:date>2011-11-28T21:48:18Z</dc:date>
    </item>
  </channel>
</rss>

