Application Dependency question (l thought l knew it)

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Application Dependency question (l thought l knew it)

L6 Presenter



A bit confused now :0


My policy as below:




So port 80 is allowed when l attempting to connect to the device over the web browser (Chrome) but after Palo actually identified that this is not a "panos-web-interface" app (based on tcp 3 way handshake and some data) didn't the response to the request.  I understood that there is no other way to do it unless you got a sufficient data to identified the app hence fist packet is allow based on destination port and session is created. 


Another policy snip:




This may not be the best example but for "http-video" (along with other app`s) my Depends on Applications: web-browsing.

My question is what is classified as a web-browsing (it is purely any web-browser request or something more specific) and what else will be allowed if my policy permit two application: https-video and web-browsing? What if l will be surfing the lnternet over the Chrome doest it means that any web-browsing traffic (requests) is allowed and will be successful ? 





L6 Presenter

Hello again,


Now l can see when enabled "Log at Session Start" that this is the same session ID and can see how the app is changing from parent to the child. Nice explanation! 




Do you know if the child app which depends on the application (let's say web-browsing) because it is using the same port 80 (or because it is working in the conjunction/over the web-browsing app). ln our case SSL port 443.



The child app depends on the parent, because the child can only be identified _after_ the parent has been identified by AppID (the first thing AppID sees is the parent's behavior, so identifies as the parent, then the session starts to send child payload and AppID can change to the child app)

The parent app is sort of the transport layer for the child app



Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

Great! Exactly what l wanted to understand. Thanks as always

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!