Application override

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Application override

L2 Linker

 

Hello,

Application Override to a custom application will force the firewall to bypass Content and Threat inspection

I've read several documents but I still don't understand the point of doing this. What's the point?

 

Thanks

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@Sarou22   Please read this 

 

In general, you would use an application override policy if your custom application is not being correctly detected AND the PA is assigning the flow to a DIFFERENT built in application.

 

The application override then prevents the upper layer inspection as and thus prevents the misclassification of the traffic.

If your custom application successfully matches the traffic, then no application override is needed.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

View solution in original post

3 REPLIES 3

L4 Transporter

Hi @Sarou22 

Application override forcibly bypasses the AppID process and sets a session to match a manually configured Application name. Any sessions processed like this will not be scanned by parallel processing and will be offloaded to fastpath

 

For most use cases, we recommend creating a simple custom application with as few attributes as possible, as the app override will bypass scanning or signature detection. It will simply identify a session as the custom application and take no further action. This can be a very simple but powerful tool to help identify internal applications and improve throughput as the session is offloaded to hardware immediately, but please consider the security implications.

The following links explain with more details about Application Override

https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-create-an-application-ov...

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRoCAK

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0

 

 

PCSPI, PCNSCx3,PCNSEx4,, PCSAE,PCDRA, ISC2 CC

Cyber Elite
Cyber Elite

@Sarou22   Please read this 

 

In general, you would use an application override policy if your custom application is not being correctly detected AND the PA is assigning the flow to a DIFFERENT built in application.

 

The application override then prevents the upper layer inspection as and thus prevents the misclassification of the traffic.

If your custom application successfully matches the traffic, then no application override is needed.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

Thank you very much 

  • 1 accepted solution
  • 858 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!