<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Policy is passing the service which is not configured in policy. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410395#M92591</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;As a best practice, I would recommend you use the Application rather than the port.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jun 2021 18:29:41 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2021-06-01T18:29:41Z</dc:date>
    <item>
      <title>Security Policy is passing the service which is not configured in policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410181#M92562</link>
      <description>&lt;P&gt;We have created a VPN to Trust rule for just FTP and SSH Service for server in which we have Allowed only those services with application any. But the some of the traffic is passing with the some random service port with the same rule with application ftp which is not mention in security policy. Any Idea why is this happening.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (501)_LI.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34149i7E8A9E3E8595E1D2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot (501)_LI.jpg" alt="Screenshot (501)_LI.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (502)_LI.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34150iECEFE693B14BC86F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot (502)_LI.jpg" alt="Screenshot (502)_LI.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 15:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410181#M92562</guid>
      <dc:creator>MPESDC</dc:creator>
      <dc:date>2021-05-31T15:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy is passing the service which is not configured in policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410184#M92563</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183239"&gt;@MPESDC&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a special case for the application ftp. In an initial ftp connection the actual data transfer port is sent in the payload of the controlconnection. The firewall reads this and opens the additional port dynamically. This is at least the explanation for this behaviour so far.&lt;/P&gt;
&lt;P&gt;I see it here probably as you do. If you have specified exactly one port, the firewall should not allow dynamically another one - even if this breaks the ftp connection. In this situation I recommend to open a TAC case for either finaly clarification or informing them about this behaviour.&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 16:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410184#M92563</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-05-31T16:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy is passing the service which is not configured in policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410212#M92567</link>
      <description>&lt;P&gt;You may check this article and your app configuration and you can you use app overide to not only to allow passive FTP but lso to block it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFeCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFeCAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 19:31:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410212#M92567</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-05-31T19:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy is passing the service which is not configured in policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410395#M92591</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;As a best practice, I would recommend you use the Application rather than the port.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 18:29:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-is-passing-the-service-which-is-not-configured/m-p/410395#M92591</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-01T18:29:41Z</dc:date>
    </item>
  </channel>
</rss>

