<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to create policy and how to identify which ports are being used on PAN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/325109#M82941</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139406"&gt;@shafi021&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You shouldn't be looking at building out a port list, you should be looking at see what applications are being identified. Identify the applications that you are seeing come across the firewall and whether or not they should be allowed, and build out exceptions for any application that isn't being properly identified.&amp;nbsp;&lt;/P&gt;&lt;P&gt;A couple notes:&lt;/P&gt;&lt;P&gt;- It's easiest if you simply build out two application-groups for sanctioned and unsanctioned applications.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Your setup doesn't sound like they've done anything outside of just installing this box. Look at following the published best-practices and actually using your NGFW to its capabilities.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 02:11:25 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-04-28T02:11:25Z</dc:date>
    <item>
      <title>how to create policy and how to identify which ports are being used on PAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/325088#M82936</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new to Palo Alto. I recently joined the firm and they are using any any as policy for internal to Public, Internal to WAN zone. My tasks is to identify the ports which are being used and apply the ACL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question to experts is how to find out which ports are being used and how should I apply this ACL on PAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have little idea that I can check ports under traffic tab and need to create service object to apply on zones.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guys please suggest me the best approach and guide me&amp;nbsp; on how I should achieve this goal.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 21:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/325088#M82936</guid>
      <dc:creator>shafi021</dc:creator>
      <dc:date>2020-04-27T21:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: how to create policy and how to identify which ports are being used on PAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/325109#M82941</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139406"&gt;@shafi021&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You shouldn't be looking at building out a port list, you should be looking at see what applications are being identified. Identify the applications that you are seeing come across the firewall and whether or not they should be allowed, and build out exceptions for any application that isn't being properly identified.&amp;nbsp;&lt;/P&gt;&lt;P&gt;A couple notes:&lt;/P&gt;&lt;P&gt;- It's easiest if you simply build out two application-groups for sanctioned and unsanctioned applications.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Your setup doesn't sound like they've done anything outside of just installing this box. Look at following the published best-practices and actually using your NGFW to its capabilities.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 02:11:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/325109#M82941</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-04-28T02:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: how to create policy and how to identify which ports are being used on PAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/325176#M82956</link>
      <description>&lt;P&gt;If you're running 9.0 code, you can use the Policy Optimizer to help you identify what applications are currently being seen on the existing rule.&amp;nbsp; It will easily allow you to apply just these apps to the rule, or clone a new rule with the selected applications.&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/app-id-features/policy-optimizer.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/app-id-features/policy-optimizer.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Custom reports would also be very helpful to you.&amp;nbsp; You can build and save report queries with all kinds of different options to pull info from the logs, and organize it into convenient summaries.&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/view-and-manage-reports/custom-reports.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/view-and-manage-reports/custom-reports.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 15:18:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/325176#M82956</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-04-28T15:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: how to create policy and how to identify which ports are being used on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/327934#M83401</link>
      <description>&lt;P&gt;Thank you for your response guys&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 14:14:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/327934#M83401</guid>
      <dc:creator>shafi021</dc:creator>
      <dc:date>2020-05-14T14:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: how to create policy and how to identify which ports are being used on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/329100#M83582</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107710"&gt;@OwenFuller&lt;/a&gt;&amp;nbsp;, we are using PAN OS 8 and not going to be on 9 soon. I configured Netflow and I can see which ports are being used. Some of the applications on my flow analysis are showing as unknown App because my org is using some non standard ports, but I can find those ports under Traffic log on PAN. My question is, is it possible to use application and service object ( where I am going to add ports) together on Zone policy. we have 3 zones, Pub, Inside and WAN. what do you suggest , how should I proceed?&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 02:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/329100#M83582</guid>
      <dc:creator>shafi021</dc:creator>
      <dc:date>2020-05-21T02:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to create policy and how to identify which ports are being used on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/329103#M83583</link>
      <description>&lt;P&gt;Yes, you can use “any” app with a particular service port instead of a pre-defined app. &amp;nbsp;Another option is to define a custom application based on the ports used. I would also check the Monitor tab to see how Palo identifies the applications, and adjust your security policies accordingly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 02:52:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-policy-and-how-to-identify-which-ports-are-being/m-p/329103#M83583</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-05-21T02:52:59Z</dc:date>
    </item>
  </channel>
</rss>

