<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom App ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386598#M90278</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90544"&gt;@nsrini1991&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, you will need to add &lt;EM&gt;mssql-db-base &lt;/EM&gt;. you can leave the port there as you don't want to offer this application on different ports&lt;/P&gt;</description>
    <pubDate>Thu, 18 Feb 2021 13:44:09 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2021-02-18T13:44:09Z</dc:date>
    <item>
      <title>Custom App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386495#M90264</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We've created a new custom app ID (custom-sql) for the SQL server with the ports TCP/10001- TCP/10004 with the Parent app as 'mssql-db-base'. Below are the firewall rules we've in place and noticed the application is correctly classified as the parent app when checking in monitor logs but instead of the below rule, it's hitting deny rule.&lt;/P&gt;&lt;P&gt;Any idea why is it so and what should be corrected. Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name: Custom-SQL-rule&lt;/P&gt;&lt;P&gt;Source: 10.0.0.0/8&lt;/P&gt;&lt;P&gt;Source Zone: Inside&lt;/P&gt;&lt;P&gt;Destination: 172.16.0.0/16&lt;/P&gt;&lt;P&gt;Destination Zone: DMZ&lt;/P&gt;&lt;P&gt;Application: custom-sql&lt;/P&gt;&lt;P&gt;service:TCP/10001&lt;/P&gt;&lt;P&gt;Action:Allow&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 05:49:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386495#M90264</guid>
      <dc:creator>nsrini1991</dc:creator>
      <dc:date>2021-02-18T05:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386536#M90271</link>
      <description>&lt;P&gt;there is a dependency for the parent app to be allowed as well,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;since the parent app is being blocked right now, App-ID is not able to identify the child app&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 08:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386536#M90271</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-18T08:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386594#M90277</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Does this mean the firewall rule should be updated with the&amp;nbsp;&lt;EM&gt;mssql-db-base ?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Should the port TCP/10001 from the service condition can exist or it can be removed?&lt;/P&gt;&lt;P&gt;Please assist.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 13:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386594#M90277</guid>
      <dc:creator>nsrini1991</dc:creator>
      <dc:date>2021-02-18T13:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386598#M90278</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90544"&gt;@nsrini1991&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, you will need to add &lt;EM&gt;mssql-db-base &lt;/EM&gt;. you can leave the port there as you don't want to offer this application on different ports&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 13:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386598#M90278</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-18T13:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386602#M90280</link>
      <description>&lt;P&gt;Hi Tom&lt;/P&gt;&lt;P&gt;Thanks for the assistance. Final one, can you please overview on how the parent app works on this example?&lt;/P&gt;&lt;P&gt;I tried to google but not able to get any clear answers.&lt;/P&gt;&lt;P&gt;Please assist.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 14:28:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386602#M90280</guid>
      <dc:creator>nsrini1991</dc:creator>
      <dc:date>2021-02-18T14:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386603#M90281</link>
      <description>&lt;P&gt;it's how APP-ID works:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. first a syn packet comes un, firewall checks if the source zone/ip, destination zone/ip, destination port and protocol are allowed somewhere (skips app for now)&lt;/P&gt;&lt;P&gt;if yes: session is created, if no, packet is discarded&lt;/P&gt;&lt;P&gt;2. handshake completes and first payload is transferred, app-id checks if anything can be identified (eg. http GET&amp;nbsp; = web-browsing)&lt;/P&gt;&lt;P&gt;at this stage most of the parent apps will be identified as they display the most basic behavio.&lt;/P&gt;&lt;P&gt;Security rules are re-evaluated to see if this app is allowed to pass, if yoes, the session carris on, if no, the session is discarded&lt;/P&gt;&lt;P&gt;This is where dependencies require their parent app to be allowed somewhere in the rulebase&lt;/P&gt;&lt;P&gt;3. session continues to transfer payload and a child-app is detected, security rules are evaluated once more to see if child-app is allowed&lt;/P&gt;&lt;P&gt;if yes, sesion is allowed to complete, if no session is discarded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 14:39:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/386603#M90281</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-18T14:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/390778#M90723</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So basically, there is no "implicit" use of an official app on a custom app-id, even if a parent application is defined?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 21:21:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id/m-p/390778#M90723</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2021-03-11T21:21:49Z</dc:date>
    </item>
  </channel>
</rss>

