APP-ID and HIgh Port range

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

APP-ID and HIgh Port range

L4 Transporter

Is ther a range of tcp/udp ports that do not have a APP-ID in appipedia? I ask b/c as we are migrationg over 10k rules we are aware not all of them will have PA app-id assoicated so we are trying to filter out those ports and jsut curious is there a acutal port range or specific ports that do not have APPID's

1 REPLY 1

Cyber Elite
Cyber Elite

hi @clyde.franklin

 

App-ID works slightly different

each appliucation does have a default port, but app-id will work across all ports : if you open a webserver's port 15999 for example app-id will identify web-browsing because it sees the http GET

the port associated to web-browsing will only be detrimental when your security policy has 'application-default' in the security policy, which limits which ports are allowed by initial SYN packets

 

eg. if there is only 1 with web-browsing and DNS and service app-default, then the drop rule only SYN packets on ports 80, 8080 and 53 will be allowed

if the service for that rule is set to 'any', all ports will be allowed, but as soon as payload starts to flow and app-id is not able to match web-browsing or DNS the session will be discarded

 

there are also a few apps that are tcp/dynamic, which means they are supposed to use any random port

if you're migrating from a different platform a good method is, for any rules that have you wondering which apps are hit, to duplicate the policy and add the apps you know in the top rule, then run reports/show logs on the second rule to see which apps you've missed, then add them to the top rule till there are no more sessions hitting the second policy, or only unwanted apps hit it, then delete the rule

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1538 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!