<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Difference between app base rule and service base rule. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-app-base-rule-and-service-base-rule/m-p/361912#M88240</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some queries,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) what is the difference between the App base rule and Service base rule?&lt;/P&gt;&lt;P&gt;2) For security purpose which one is a more secure app or service base rule?&lt;/P&gt;&lt;P&gt;3) What is the benefit of using App base rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2020 15:05:59 GMT</pubDate>
    <dc:creator>OsamaKhan</dc:creator>
    <dc:date>2020-11-10T15:05:59Z</dc:date>
    <item>
      <title>Difference between app base rule and service base rule.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-app-base-rule-and-service-base-rule/m-p/361912#M88240</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some queries,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) what is the difference between the App base rule and Service base rule?&lt;/P&gt;&lt;P&gt;2) For security purpose which one is a more secure app or service base rule?&lt;/P&gt;&lt;P&gt;3) What is the benefit of using App base rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 15:05:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-app-base-rule-and-service-base-rule/m-p/361912#M88240</guid>
      <dc:creator>OsamaKhan</dc:creator>
      <dc:date>2020-11-10T15:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between app base rule and service base rule.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-app-base-rule-and-service-base-rule/m-p/361931#M88243</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/116059"&gt;@OsamaKhan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;1) what is the difference between the App base rule and Service base rule?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Service is only looking at layer-4, so if you open 25/tcp for example expecting to only allow SMTP traffic that doesn't really work. The only thing you're doing is allowing traffic to the specified host on 25/tcp.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;App-ID is all signature based, so if you allow SMTP with application-default you'll only be allowing SMTP traffic. If that app-id's signature picks up anything else, the traffic won't match that rulebase entry.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) For security purpose which one is a more secure app or service base rule?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;It's always going to be App-ID. App-ID is checking to make sure that the traffic that you're trying to allow is what is actually being identified. If you simply specify any application on a service object you're just opening a port.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) What is the benefit of using App base rules?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;You're verifying that what you are trying to allow is what is actually being passed. If the traffic signature matches an app-id that you aren't allowing the traffic will be dropped.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 17:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-app-base-rule-and-service-base-rule/m-p/361931#M88243</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-11-10T17:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between app base rule and service base rule.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-app-base-rule-and-service-base-rule/m-p/362895#M88307</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Just to expand on question 3 a bit and what BPry already mentioned. Lets say you have a policy where you only want your internal DNS or domain controllers to access DNS from the internet using a secure DNS provider. Your Application based policy would ensure that the internal DNS servers are actually using DNS to go to the external secure DNS provider. This would prevent a malicious actor from exfiltrating data out from any system using port 53 or DNS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hint: Please do this as it is very secure and often overlooked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 23:08:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-app-base-rule-and-service-base-rule/m-p/362895#M88307</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-11-12T23:08:58Z</dc:date>
    </item>
  </channel>
</rss>

