Application Override Question

Reply
Highlighted
L1 Bithead

Application Override Question

Hi All,

 

I got this question from the learning center for the PCNSE practice exam. Dont know if its allowed to post the screenshot here.

 

app-override.PNG

 

From my understanding of using the application override, the firewall stops any further content inspection. It was also stated on the admin guide:

If you define an application override, the firewall stops processing at Layer-4. The custom application name is assigned to the session to help identify it in the logs, and the traffic is not scanned for threats.

 

Does using a built-in application on an app-override policy allows the firewall to perform content and threat protection?

 

Thanks and regards,

Jon

 

 

 

 

 

Tags (1)
L5 Sessionator

Re: Application Override Question

Hey Jon,

 

Layer7 processing for an app will only stop when using a PBF rule if you override the app to a custom one i.e "MyCustomApp". Overriding the traffic to an existing app such as web-browsing in this example will keep the content inspection enabled.

 

Thanks,

Luke.

L7 Applicator

Re: Application Override Question

Hello,

So if you use Application Override, Content-ID does not occur.

 

  • For example, if you build a custom application that triggers on a host header www.mywebsite.com, the
    packets are first identified as web-browsing and then are matched as your custom application (whose
    parent application is web-browsing). Because the parent application is web-browsing, the custom
    application is inspected at Layer-7 and scanned for content and vulnerabilities.

  • If you define an application override, the firewall stops processing at Layer-4. The custom application
    name is assigned to the session to help identify it in the logs, and the traffic is not scanned for threats.

 

This is from the admin guide on page 580.

 

Regards,

L7 Applicator

Re: Application Override Question

Hello,

Also as a side note. I have also looked at the practice exam and there do seem to be errors in the answers. Dont trust the practice questions, go by what the guides state.

 

Regards,

L1 Bithead

Re: Application Override Question

Thanks for the reply.

 

So just to confirm, threat content scanning will still be enabled for app-override policies using:

 

1. pre-built applicaition

2. custom application with a pre-built parent app

 

??

L1 Bithead

Re: Application Override Question

Thanks Luke.

L1 Bithead

Re: Application Override Question

I tried to lab this up.

 

I created a custom app with for tcp/80 with the parent application as web-browsing. Enable scanning for file types, viruses, data patterns. Then added that application to an application override policy. I tried to download the eicar test file for http. The download proceeded.

 

When i changed the application override to use the application web-browsing. The file got blocked.

I may need clarification on this line:  Because the parent application is web-browsing, the custom
application is inspected at Layer-7 and scanned for content and vulnerabilities.

 

L5 Sessionator

Re: Application Override Question

Hey @Jonathan_Panes 

 

When you create a custom application, it will take precedence over the predefined applications. When you're using your custom app-id in the App override, the Layer7 will stop. When you put web-browsing in the App Override, Layer7 can continue, hence you could download the file.

 

Thanks,

Luke.

L1 Bithead

Re: Application Override Question

Can anyone point me to using/applying an override to a predefined application, like web-browsing?

 

All I find are documents on how to create a custom application, create an override for it. I want to create a rule that allows web-browsing AppID over a port other than 80 or 8080.

Adding Service TCP_12345 for example, will allow any app using port 12345. So that answer ain't valid.

 

When creating an override on web-browsing with tcp port 12345. The policy(/ies) with web-browsing allowed will do nothing with the created override even though all the zones sources and targets are provided and match.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!