Custom App signature and App pushed from PA update

Reply
L4 Transporter

Custom App signature and App pushed from PA update

 

What if we create creates a custom application containing Layer 7 signatures.

And after few days the PA send the Latest APP and  Threat updates and we download those in the PA


What will happen if the update contains an application that matches the same traffic signatures as the custom application?

 

or

 

which thing  is hit first custom app or application pushed from PA when both have same signatures?

 

My understanding is that Custom APP should have preference?

 

 

L2 Linker

Re: Custom App signature and App pushed from PA update

I found a KB article that speaks directly to your question.

It supports your understanding - Custom App-ID > predefined applications:

 

Custom Applications take precedence over predefined applications (including new Applications released in content updates) for matching traffic types when the traffic matches both a custom and local pattern. This is also true for VSYS specific custom applications (applications defined for individual VSYS).

 

Note: This action will take affect on the traffic immediately after a commit completes.

 

The Custom App will be matched without modifications to the security policy when a rule is defined with "application any". This occurs automatically even if the Custom Application is not used in a security policy or forced through the App Override when matching a rule with "application any", so long as the new application signature is defined correctly.


 

L4 Transporter

Re: Custom App signature and App pushed from PA update

Many Thanks I was exactly looking for that.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!