Custom App-ID with just source and destination ip address

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Custom App-ID with just source and destination ip address

L0 Member

Hi,

 

I have some traffic on a tap interface that I would like to create an APP-ID to identify it in the monitor logs. This a seperate network with its own custom application and functions. I have done some pcap's and can't see distinct data that relate to the context values in the custom App-ID form. Is there a list of what the context values are/mean?   Is it possible to just create an App-ID with the source-ipaddress:port and destination-ipaddress:port? There are multiple sources talking to multiple servers but it is not a generic application available on the internet.  The ports seem to be distinct from the common ports used in other applications.

Any help at all would be very gratefully recieved.

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi @ConorMc ,

 

Yes, you can use Application Override to assign traffic to custom applications.  https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0

 

This 1st step for Application Override is to define the custom application.  If the source or destination port is consistent, you can define that in the custom application.

 

Then you create your Application Override policy based upon the source and/or destination IP addresses.  The traffic will then be assigned the custom App-ID and you can track it in your logs and use it in your security policy.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Thanks for your help Tom,

I'll look at that now. Just a question, this seems to bypass the Content and Threat inspection for the traffic. I need the traffic to be inspected for malware etc. The system is an IDS for traffic on private networks that is sent to the Firewall tap interface. 

Regards,

Conor.

  • 53 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!