Application and services in security policy rules

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Application and services in security policy rules

L1 Bithead

Hi I have a question,

 

 

 

Following rule,

 

Application allowed- DNS,SSL,WEB-Browsing

 

Service allowed - TCP port 22

 

jatinsingh06_1-1654734297058.png

I understand DNS, SSL and Web-browsing would be allowed on port 22, but my question is SSH  traffic  would be allowed by this rule as I am allowing port-22 via service.?

 

Also My second question, would DNS traffic  be allowed on its standard  port 53 via this rule?

 

 

My understanding is Palo matches Both Services and Application together, hence SSH traffic would be blocked in this case and DNS traffic on port 53 would  also be blocked?

 

Referring this article - https://live.paloaltonetworks.com/t5/blogs/what-are-applications-and-services/ba-p/342508

 

 

10 REPLIES 10

Cyber Elite
Cyber Elite

The service configuration limits which ports the applications are allowed to use

Setting tcp-22 in the services limits ALL applications to only be allowed through tcp:22 (so DNS will need to use TCP 22 instead of UDP 53)

 

if DNS needs to be allowed too, you'll need to add udp53 to the services

 

 

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

Cyber Elite
Cyber Elite

Hello,

While there maybe a reason for restricting the application traffic, I would break these out into their own separate policies. This way you have tighter control over applications and which ports they can/should use.

 

Regards,

Hi Reaper,

That makes sense but just confirming SSH traffic will also be blocked in the case as I have not allowed SSH in application section?

 

Please confirm

L2 Linker

break application  out into their own separate security policies and define whatever port you desire to use except you want all the app on the same port 22 and also define udp port.

Simplicity is the friend of Security, whilst complexity is the Enemy. (Bruce Schneier) PCNSE,CCSA, SEC-Plus, CCNA Security
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!