<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use destination networks even with App-ID specified? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/use-destination-networks-even-with-app-id-specified/m-p/306449#M79617</link>
    <description>&lt;P&gt;Thanks for sharing your input&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;.!&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2020 09:12:30 GMT</pubDate>
    <dc:creator>btenberge</dc:creator>
    <dc:date>2020-01-13T09:12:30Z</dc:date>
    <item>
      <title>Use destination networks even with App-ID specified?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-destination-networks-even-with-app-id-specified/m-p/306103#M79544</link>
      <description>&lt;P&gt;I've been creating security rules to allow Traps Management (with the traps-management-service App-ID) pretty tightly by also defining destination networks (using FQDN objects for the multiple &amp;lt;tenant&amp;gt;&lt;SPAN&gt;.traps.paloaltonetworks.com and common contentprod and distributions hosts).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;According to the documentation on&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/traps/tms/traps-management-service-admin/get-started-with-tms/enable-access-tms.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/traps/tms/traps-management-service-admin/get-started-with-tms/enable-access-tms.html&lt;/A&gt;&amp;nbsp;it should be enough to simply use the App-ID and keep it at that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So now that got me thinking, does the traps-management-service App-ID take destination networks into account?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Am I too paranoid doing things like this, or is it good practice to keep security rules as tight as possible, even with App-ID's?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 11:34:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-destination-networks-even-with-app-id-specified/m-p/306103#M79544</guid>
      <dc:creator>btenberge</dc:creator>
      <dc:date>2020-01-09T11:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Use destination networks even with App-ID specified?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-destination-networks-even-with-app-id-specified/m-p/306185#M79563</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/19436"&gt;@btenberge&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I believe that the traps-management-service signature actually takes the certificate of the connection into account, so the app-id itself should be relatively bulletproof.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like anything else, how you should configure this really depends on your environments risk level. I have some organizations where I limit access to set destination addresses for any rule allowing outbound traffic; and I have others where the app-id itself is more than sufficient. If you utilize app-id to limit access, you are still allowing a handshake to take place at minimum. Some orgs will find that acceptable, others won't.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From an over-arching answer I'll say this, the vast majority of environments shouldn't feel like they need to limit app-id use to specified destinations. Even in highly secure environments, I generally would only go to the lengths you are going to on machines that actually have access to access sensitive information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 19:39:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-destination-networks-even-with-app-id-specified/m-p/306185#M79563</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-01-09T19:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Use destination networks even with App-ID specified?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-destination-networks-even-with-app-id-specified/m-p/306449#M79617</link>
      <description>&lt;P&gt;Thanks for sharing your input&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;.!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 09:12:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-destination-networks-even-with-app-id-specified/m-p/306449#M79617</guid>
      <dc:creator>btenberge</dc:creator>
      <dc:date>2020-01-13T09:12:30Z</dc:date>
    </item>
  </channel>
</rss>

