app not show on application field on policy based forwarding

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

app not show on application field on policy based forwarding

L2 Linker

Hi community,

 

what is the reason one app not show applications field/

We need create one policy with one app that show on applications, but when I check in PBF the app is not show. 

 

The app name "supremo" use default port tcp/443 and Implicitly Uses:  web-browsing.

What is the reason ?

2 accepted solutions

Accepted Solutions

L6 Presenter
The reason is you can't use the full list of apps in PBF that exist in applipedia. It's a misnomer that you can use apps like Facebook or Netflix and "route" those packets.

View solution in original post

Routing decision has to be made based on first packet.

First packet in TCP based application is SYN.

Based on SYN it is not possible to identify application yet and make routing decision.

 

For example in case of web-browsing application is identified on 5th packet.

SYN - client to server

SYN ACK - server to client

ACK - client to server

HTTP GET - client to server

And now when website sends back website Palo shifts application to web-browsing.

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

4 REPLIES 4

L6 Presenter
The reason is you can't use the full list of apps in PBF that exist in applipedia. It's a misnomer that you can use apps like Facebook or Netflix and "route" those packets.

Routing decision has to be made based on first packet.

First packet in TCP based application is SYN.

Based on SYN it is not possible to identify application yet and make routing decision.

 

For example in case of web-browsing application is identified on 5th packet.

SYN - client to server

SYN ACK - server to client

ACK - client to server

HTTP GET - client to server

And now when website sends back website Palo shifts application to web-browsing.

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cool, thank you.


@mss.support wrote:

Cool, thank you.


Trust me it was a bummer when I found this as well. 

 

"Application routing" devices like touted in SD-WAN solutions / Meraki, Viptela, or even Riverbed's SteelConnect tout application based routing.  I've not really delved into these solutions, and can't understand how there isn't some sort of a hit as application shifts occur which could change a routed path.  That said I would love it if Palo could use a similar solution.

  • 2 accepted solutions
  • 5247 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!