<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can someone explain to me like I'm 5 what App-IDs are? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344654#M86218</link>
    <description />
    <pubDate>Wed, 19 Aug 2020 20:38:42 GMT</pubDate>
    <dc:creator>AndrewPaloAlto</dc:creator>
    <dc:date>2020-08-19T20:38:42Z</dc:date>
    <item>
      <title>Can someone exsplaine to me like I'm 5 what App-IDs are?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344646#M86216</link>
      <description>&lt;P&gt;So I need to update my PanOS on my PA-3020, but&amp;nbsp;because I have a&amp;nbsp;&lt;I&gt;mission-critical&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;network I need to avoid downtime as much as possible.&amp;nbsp; In the walk-through for the PanOS upgrade, it says 'any change a content releases introduces that affects App-ID could cause downtime.'&amp;nbsp;&amp;nbsp;&lt;BR /&gt;I was not fully clear on what an App-ID is, and why it might change from an update.&amp;nbsp; If I have a few rules in place regarding allowing some configured alerts, are those configured alerts considered App-IDs?&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can someone please shed some light on this for me?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;I'm going from PanOS 9, to 10.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 20:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344646#M86216</guid>
      <dc:creator>AndrewPaloAlto</dc:creator>
      <dc:date>2020-08-19T20:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone explain to me like I'm 5 what App-IDs are?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344654#M86218</link>
      <description />
      <pubDate>Wed, 19 Aug 2020 20:38:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344654#M86218</guid>
      <dc:creator>AndrewPaloAlto</dc:creator>
      <dc:date>2020-08-19T20:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone exsplaine to me like I'm 5 what App-IDs are?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344657#M86219</link>
      <description>&lt;P&gt;*explain&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 20:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344657#M86219</guid>
      <dc:creator>AndrewPaloAlto</dc:creator>
      <dc:date>2020-08-19T20:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone exsplaine to me like I'm 5 what App-IDs are?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344701#M86227</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149938"&gt;@AndrewPaloAlto&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;App-IDs are a collection of identifiable information (traffic signatures, protocol decoding, heuristics) which is able to identify traffic to a particular application without relying solely on port information like in older L4 deployments. These are updating constantly because the applications themselves don't stay the same, or PAN removes false-positives or expands coverage of an app-id so that it properly identifies even more traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An example on why this can cause an outage would be if I configured a security rulebase entry that allowed the app-id SSL over a service object that maps to tcp/636. If a future content update expands coverage of the app-id ldap so that it starts matching traffic within my environment, I would no longer have a security rulebase entry that would allow the traffic to pass. IE: A rule allowing ssl on tcp/636 wouldn't allow traffic being identified as ldap on tcp/636 because the rule no longer matches the traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If I have a few rules in place regarding allowing some configured alerts, are those configured alerts considered App-IDs?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;This question is&amp;nbsp;unclear in what you are actually asking. What exactly do you mean when you say that you have rules in place regarding allowing some configured alerts? Configured alerts for what, the firewall or some industrial equipment? App-IDs are the applications that you specify within the security rulebase entires; some of these are application containers which are made from multiple individual app-ids, but that's getting slightly into the weeds of things.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 03:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/344701#M86227</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-20T03:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone exsplaine to me like I'm 5 what App-IDs are?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/345009#M86276</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149938"&gt;@AndrewPaloAlto&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;So I need to update my PanOS on my PA-3020, but&amp;nbsp;because I have a&amp;nbsp;&lt;I&gt;mission-critical&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;network I need to avoid downtime as much as possible.&amp;nbsp; In the walk-through for the PanOS upgrade, it says 'any change a content releases introduces that affects App-ID could cause downtime.'&amp;nbsp;&amp;nbsp;&lt;BR /&gt;I was not fully clear on what an App-ID is, and why it might change from an update.&amp;nbsp; If I have a few rules in place regarding allowing some configured alerts, are those configured alerts considered App-IDs?&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can someone please shed some light on this for me?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;I'm going from PanOS 9, to 10.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I think what you're referring to is what might happen if Palo Alto adds to or changes how an "application" is identified by the firewall.&amp;nbsp; Palo Alto uses multiple identifying characteristics of network traffic to create an "application" definition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For instance on 7-23-2020, Palo Alto released application updates which changed how some applications are identified.&amp;nbsp; Before this release traffic would have been seen simply as "cip-ethernet-ip-base" after this update the same traffic which the firewall saw could further be identified by the following applications:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cip-ethernet-ip-disable-io (functional)&lt;BR /&gt;cip-ethernet-ip-disable-sfc (functional)&lt;BR /&gt;cip-ethernet-ip-enable-io (functional)&lt;BR /&gt;cip-ethernet-ip-enable-sfc (functional)&lt;BR /&gt;cip-ethernet-ip-read-mod-write (functional)&lt;BR /&gt;cip-ethernet-ip-read-tag (functional)&lt;BR /&gt;cip-ethernet-ip-read-tag-frag (functional)&lt;BR /&gt;cip-ethernet-ip-run (functional)&lt;BR /&gt;cip-ethernet-ip-stop (functional)&lt;BR /&gt;cip-ethernet-ip-test-mode (functional)&lt;BR /&gt;cip-ethernet-ip-write-tag (functional)&lt;BR /&gt;cip-ethernet-ip-write-tag-frag (functional)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if you wrote a rule that ONLY allow the previous application of&amp;nbsp;cip-ethernet-ip-base, after the application update download to your firewall it's entirely possible these new applications wouldn't have been allowed since they weren't previously allowed in your security policy.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 16:54:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/345009#M86276</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2020-08-21T16:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone exsplaine to me like I'm 5 what App-IDs are?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/345073#M86285</link>
      <description>&lt;P&gt;By the way, you&amp;nbsp; will not be able to upgrade 3020 to panos 10.&lt;/P&gt;&lt;P&gt;9.1.x supported but 10 not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 22 Aug 2020 15:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-someone-exsplaine-to-me-like-i-m-5-what-app-ids-are/m-p/345073#M86285</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-08-22T15:12:07Z</dc:date>
    </item>
  </channel>
</rss>

