<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application vs Services in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356199#M87633</link>
    <description>&lt;P&gt;Application and services are handled seperatly, that means you will need to list all applications that you need, and all services that you need. an example if the traffic has been identified as Facebook:Port 80,443, then application tab should list facebook and services set to selected then services will need to list all ports that facebook will need. another exmple if the firewall identified the traffic as Unknown TCP:Port 7010, and application tab lists Unkown-tcp, but services selected and port 7010 not listed, the traffic wont match the rule.&lt;/P&gt;&lt;P&gt;hope now it is more clear.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Oct 2020 08:30:52 GMT</pubDate>
    <dc:creator>Abdul-Fattah</dc:creator>
    <dc:date>2020-10-14T08:30:52Z</dc:date>
    <item>
      <title>Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/355608#M87562</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have a couple of questions in application vs services.&lt;/P&gt;&lt;P&gt;1. I have to permit a list of services for a particular traffic. In those list some of them are already in the applications like DNS, IMAP, Pop3 and I need to create some services with custom port. Now do I add these applications and the custom services in the same rule or does it have to be in two different rules ?&lt;/P&gt;&lt;P&gt;2. I need to permit bitdefender/kaspersky antivirus traffic. As per the application it uses only tcp 80/443 as standard port. But I do have a list of services which has custom ports like tcp 7075. Do i need to add as a service or add as an application and give any (instead of application-default) ?&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 07:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/355608#M87562</guid>
      <dc:creator>KrishnanR</dc:creator>
      <dc:date>2020-10-11T07:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/355636#M87564</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;1- You can add the application and all ports to same rule, as the application wont be identified based on the port it uses but here you will have to allow all services like also 53, 143...&lt;/P&gt;&lt;P&gt;2- you can choose the application and set service to any, that should work but not best practice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 15:21:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/355636#M87564</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-10-11T15:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/355712#M87572</link>
      <description>&lt;P&gt;Hi Abdul,&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Now If I add applications for eg DNS, then do i need to allow 53 as well ? Then If I permit 53 in service and I need to permit some customer service like 7010, then I will be adding 7010 as well. WIll the application DNS be looking for service 7010 as well ? or how is the behavior ?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 08:53:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/355712#M87572</guid>
      <dc:creator>KrishnanR</dc:creator>
      <dc:date>2020-10-12T08:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/355744#M87578</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141720"&gt;@KrishnanR&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you will need to add all ports that the applications will use because in the services tab&amp;nbsp; "Selected" will be set.&lt;/P&gt;&lt;P&gt;each application will use the ports it needed, DNS works on normally on Port 53, so it will use this port.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 10:09:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/355744#M87578</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-10-12T10:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356193#M87628</link>
      <description>&lt;P&gt;Thanks for your message.&lt;/P&gt;&lt;P&gt;If I have a list of applications like dns, https along with some services like TCP-7010(not related to dns or https), these applications have no relation with the services I am going to mention. So should it be in a single policy ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 07:33:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356193#M87628</guid>
      <dc:creator>KrishnanR</dc:creator>
      <dc:date>2020-10-14T07:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356195#M87630</link>
      <description>&lt;P&gt;well that depends how you will organize your security policies, so when you search for a policy your created before it will make sense to the admin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 07:50:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356195#M87630</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-10-14T07:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356198#M87632</link>
      <description>&lt;P&gt;Dear Abdul,&lt;/P&gt;&lt;P&gt;Thanks for your reply. I mean can I add them both in a single policy itself rather than creating two different policies one for App-ID and another for Services related. Will that be fine or that may cause any issue ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 08:06:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356198#M87632</guid>
      <dc:creator>KrishnanR</dc:creator>
      <dc:date>2020-10-14T08:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356199#M87633</link>
      <description>&lt;P&gt;Application and services are handled seperatly, that means you will need to list all applications that you need, and all services that you need. an example if the traffic has been identified as Facebook:Port 80,443, then application tab should list facebook and services set to selected then services will need to list all ports that facebook will need. another exmple if the firewall identified the traffic as Unknown TCP:Port 7010, and application tab lists Unkown-tcp, but services selected and port 7010 not listed, the traffic wont match the rule.&lt;/P&gt;&lt;P&gt;hope now it is more clear.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 08:30:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356199#M87633</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-10-14T08:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356202#M87634</link>
      <description>&lt;P&gt;Dear Abdul,&lt;/P&gt;&lt;P&gt;Thanks for your quick response. So in the same rule, I can add these. This will work ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KrishnanR_0-1602665645064.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28196i94EF2642751B3F90/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KrishnanR_0-1602665645064.png" alt="KrishnanR_0-1602665645064.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I saw the following rule in the demo system. It means in a single rule it should be fine I guess&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KrishnanR_1-1602665699920.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28197iADB5BCA85F23018B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KrishnanR_1-1602665699920.png" alt="KrishnanR_1-1602665699920.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 08:52:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356202#M87634</guid>
      <dc:creator>KrishnanR</dc:creator>
      <dc:date>2020-10-14T08:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356217#M87635</link>
      <description>&lt;P&gt;no that will not work, because services is selected and only 4001 is allowed, when selected you will need to enter all port that you want to allow or deny that means the dns port.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 09:44:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356217#M87635</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-10-14T09:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356231#M87636</link>
      <description>&lt;P&gt;But if you look at the rule which I saw in demo appliance it had ping and other applications with a custom service.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 10:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356231#M87636</guid>
      <dc:creator>KrishnanR</dc:creator>
      <dc:date>2020-10-14T10:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: Application vs Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356236#M87640</link>
      <description>&lt;P&gt;ping doesnt need a port, and for ms-rdp probably they are using NAT or even 3389 defined in same TCP4001. as i already mentinied that is how security policy in PA works.&lt;/P&gt;&lt;P&gt;good luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 11:59:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-vs-services/m-p/356236#M87640</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-10-14T11:59:06Z</dc:date>
    </item>
  </channel>
</rss>

