Custom App signature and App pushed from PA update

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Custom App signature and App pushed from PA update

Cyber Elite
Cyber Elite

 

What if we create creates a custom application containing Layer 7 signatures.

And after few days the PA send the Latest APP and  Threat updates and we download those in the PA


What will happen if the update contains an application that matches the same traffic signatures as the custom application?

 

or

 

which thing  is hit first custom app or application pushed from PA when both have same signatures?

 

My understanding is that Custom APP should have preference?

 

 

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

L2 Linker

I found a KB article that speaks directly to your question.

It supports your understanding - Custom App-ID > predefined applications:

 

Custom Applications take precedence over predefined applications (including new Applications released in content updates) for matching traffic types when the traffic matches both a custom and local pattern. This is also true for VSYS specific custom applications (applications defined for individual VSYS).

 

Note: This action will take affect on the traffic immediately after a commit completes.

 

The Custom App will be matched without modifications to the security policy when a rule is defined with "application any". This occurs automatically even if the Custom Application is not used in a security policy or forced through the App Override when matching a rule with "application any", so long as the new application signature is defined correctly.


 

View solution in original post

2 REPLIES 2

L2 Linker

I found a KB article that speaks directly to your question.

It supports your understanding - Custom App-ID > predefined applications:

 

Custom Applications take precedence over predefined applications (including new Applications released in content updates) for matching traffic types when the traffic matches both a custom and local pattern. This is also true for VSYS specific custom applications (applications defined for individual VSYS).

 

Note: This action will take affect on the traffic immediately after a commit completes.

 

The Custom App will be matched without modifications to the security policy when a rule is defined with "application any". This occurs automatically even if the Custom Application is not used in a security policy or forced through the App Override when matching a rule with "application any", so long as the new application signature is defined correctly.


 

Many Thanks I was exactly looking for that.

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 2125 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!