<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: APP-ID: Target app and Depends ON APPs over more then one Security Rule! YES or NOT? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/383570#M89979</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer, that is helping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;This is just a management/operation decision. I like to create a general internet browsing policy that includes ssl and web-browsing, and then create more specific allowed application entries above that.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;If you write "above" then you have the general internet browsing poilcy in the end of the ruleset? Ok, as you said, the position is not relevant with APP ID, only if you have other restriction of the tuple 6 criterias or URL matching criteria. If i understand the flow correct.&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Feb 2021 08:54:31 GMT</pubDate>
    <dc:creator>fhu_omi</dc:creator>
    <dc:date>2021-02-03T08:54:31Z</dc:date>
    <item>
      <title>APP-ID: Target app and Depends ON APPs over more then one Security Rule! YES or NOT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/381549#M89757</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't find a real answer for the question, if its nessessary to add "Depends On" Apps in the SAME security rule or is it also possible to add this in the security rules before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example for specific app and all "Depends on" in have to be in the same security rule:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV0CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV0CAK (&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;need to have one of the following apps need to be allowed in the same rule t&lt;SPAN&gt;o allow facebook-posting&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;)&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClirCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClirCAC (last example in the post)&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Official Admin Guide, says all depends on Apps have to be in the same rule.&lt;/LI&gt;&lt;LI&gt;PaloAlto guy statement&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in the other side: Not nessessary or recommendet in the same rule:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/app-id-doubt/m-p/344365#M86168" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/app-id-doubt/m-p/344365#M86168 (I would generally recommend&amp;nbsp;&lt;STRONG&gt;not&amp;nbsp;&lt;/STRONG&gt;including common dependencies directly in your AnyDesk rule, because it's likely already being satisfied in your rulebase.)&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;If you clone or create a security policy ther is alway an option for "Depends On Application" to add to e existing rule instead only to the same, therefore could it be that this is also intendet to use in this way. (&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/use-application-objects-in-policy/resolve-application-dependencies.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/use-application-objects-in-policy/resolve-application-dependencies.html&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Also a demo setup, where in rule 1. is ssl and webbrowsing allowed, and in the 2.only github-base, result in that i can access github&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Because of these contradictory statements and the real experiment I am now very confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it is possible to seperate depends on Apps in a rule before as the target App with this dependencies, like my setup. Then is it that the prove that not first rule matches!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i hope somebody can help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Fabio&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 14:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/381549#M89757</guid>
      <dc:creator>fhu_omi</dc:creator>
      <dc:date>2021-01-22T14:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID: Target app and Depends ON APPs over more then one Security Rule! YES or NOT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/381854#M89778</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71244"&gt;@fhu_omi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You can absolutely separate these out without any issue, as long as the depends on app-ids are allowed&amp;nbsp;&lt;EM&gt;somewhere&amp;nbsp;&lt;/EM&gt;in the rulebase it'll work perfectly fine.&lt;/P&gt;
&lt;P&gt;So if you take a look at youtube-streaming for example, it depends on youtube-base. You don't need to include youtube-streaming and youtube-base in the same rulebase entry, and you can separate them into two separate entries and it would work perfectly fine. As soon as the traffic is identified under the new app-id, the firewall will re-scan the security rulebase and match to whatever rulebase entry you have associated with the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 04:23:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/381854#M89778</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-25T04:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID: Target app and Depends ON APPs over more then one Security Rule! YES or NOT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/381877#M89783</link>
      <description>&lt;P&gt;i concur with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; : you don't need to have dependencies in the same rule. I do want to zoom in on your last paragraph to hopefull ylft some more of the condfusion surrounding this topic:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"If it is possible to seperate depends on Apps in a rule before as the target App with this dependencies, like my setup. Then is it that the prove that not first rule matches!"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for every session the rulebase will actually evaluate the security rulebase multiple times:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. when&amp;nbsp; a SYN packet comes in, only the 6-tuple is available (srcIP,srcZone,dstIP,dstZone,dstPort,Proto) so the apps in rules will be ignored to find a matching rule&lt;/P&gt;&lt;P&gt;2. when the initial app is detected, the rulebase will again be evaluated to see if a rule is found that matches the app (this is where web-browsing, ssl etc are detected as we're only 4-6 packets into a session)&lt;/P&gt;&lt;P&gt;3. as the session passes more packets, the 'app' will start to transmit more payload that can be identified as something more specific, so this could be one of the app-&lt;STRONG&gt;base&lt;/STRONG&gt; applications, so the firewall checks if that app matches a rule&lt;/P&gt;&lt;P&gt;4. with even more payload being transferred, an even more specific app can be detected. This is where the apps live that are &lt;STRONG&gt;dependent&lt;/STRONG&gt; on a more generic 'parent' app, because it takes so many packets before it can be properly identified. At this stage another rulebase evaluation takes place, so this app can actually sit in a different rule than the above 'parents'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 09:02:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/381877#M89783</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-25T09:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID: Target app and Depends ON APPs over more then one Security Rule! YES or NOT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/382896#M89888</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok that makes absolutly sense, thank you very much.&lt;/P&gt;&lt;P&gt;But what happens if i add in every security rule, the desired APPID and the "Parent APPIDs". For example, two seperate security rules with different AppIDs, like 1. pastebin and 2. github, but both have the ssl, web-browsing as depend on (this is only en example, one of them implicity use ssl). If i add ssl and web-browsing in every rule, but with different URL Filters, because i have to restrict in both rules different SubUrlPaths. How is handling this the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there an advantage or disadvantage, if i seperate depends on AppIDs in seperate security rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because a ruleset should be readable, i think an order is good, if i alway need to search where i allow an AppID, then its difficult to read the ruleset. But i don't know if its a bad idee to build up the ruleset with needed depends on AppIDs first in the rulest and then i go more and more sepcific to the desired AppIDs. The rest of the ruleset is like first rule match, from spesific first to more and more general at the end. Now with AppID is this in my point of view the oppsit and i have to combine both methods.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Fabio&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 15:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/382896#M89888</guid>
      <dc:creator>fhu_omi</dc:creator>
      <dc:date>2021-01-29T15:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID: Target app and Depends ON APPs over more then one Security Rule! YES or NOT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/382897#M89889</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71244"&gt;@fhu_omi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The traffic is going to match the first entry that matches the traffic pattern.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) If you included ssl and web-browsing in every rule&amp;nbsp;&lt;EM&gt;without&amp;nbsp;&lt;/EM&gt;a URL Category or restricted destination configured, traffic is simply going to match to the first rulebase entry.&lt;/P&gt;
&lt;P&gt;2) When you use a URL Category to restrict the traffic, the first rule to do so is going to allow all traffic until the URL can be identified. At that time, the firewall would re-analyze the rulebase and match to the proper rule.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is there an advantage or disadvantage, if i seperate depends on AppIDs in seperate security rules?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;This is just a management/operation decision. I like to create a general internet browsing policy that includes ssl and web-browsing, and then create more specific allowed application entries above that.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 16:00:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/382897#M89889</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-29T16:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID: Target app and Depends ON APPs over more then one Security Rule! YES or NOT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/383570#M89979</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer, that is helping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;This is just a management/operation decision. I like to create a general internet browsing policy that includes ssl and web-browsing, and then create more specific allowed application entries above that.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;If you write "above" then you have the general internet browsing poilcy in the end of the ruleset? Ok, as you said, the position is not relevant with APP ID, only if you have other restriction of the tuple 6 criterias or URL matching criteria. If i understand the flow correct.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 08:54:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-target-app-and-depends-on-apps-over-more-then-one/m-p/383570#M89979</guid>
      <dc:creator>fhu_omi</dc:creator>
      <dc:date>2021-02-03T08:54:31Z</dc:date>
    </item>
  </channel>
</rss>

