06-16-2019 09:02 PM
Hi All,
I got this question from the learning center for the PCNSE practice exam. Dont know if its allowed to post the screenshot here.
From my understanding of using the application override, the firewall stops any further content inspection. It was also stated on the admin guide:
If you define an application override, the firewall stops processing at Layer-4. The custom application name is assigned to the session to help identify it in the logs, and the traffic is not scanned for threats.
Does using a built-in application on an app-override policy allows the firewall to perform content and threat protection?
Thanks and regards,
Jon
06-17-2019 01:37 AM
Hey Jon,
Layer7 processing for an app will only stop when using a PBF rule if you override the app to a custom one i.e "MyCustomApp". Overriding the traffic to an existing app such as web-browsing in this example will keep the content inspection enabled.
Thanks,
Luke.
06-17-2019 09:58 AM
Hello,
So if you use Application Override, Content-ID does not occur.
This is from the admin guide on page 580.
Regards,
06-17-2019 01:37 AM
Hey Jon,
Layer7 processing for an app will only stop when using a PBF rule if you override the app to a custom one i.e "MyCustomApp". Overriding the traffic to an existing app such as web-browsing in this example will keep the content inspection enabled.
Thanks,
Luke.
06-17-2019 09:58 AM
Hello,
So if you use Application Override, Content-ID does not occur.
This is from the admin guide on page 580.
Regards,
06-17-2019 09:59 AM
Hello,
Also as a side note. I have also looked at the practice exam and there do seem to be errors in the answers. Dont trust the practice questions, go by what the guides state.
Regards,
06-17-2019 07:31 PM
Thanks for the reply.
So just to confirm, threat content scanning will still be enabled for app-override policies using:
1. pre-built applicaition
2. custom application with a pre-built parent app
??
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!