- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
07-29-2024 06:38 AM
Hello,
Application Override to a custom application will force the firewall to bypass Content and Threat inspection
I've read several documents but I still don't understand the point of doing this. What's the point?
Thanks
07-29-2024 01:54 PM
@Sarou22 Please read this
In general, you would use an application override policy if your custom application is not being correctly detected AND the PA is assigning the flow to a DIFFERENT built in application.
The application override then prevents the upper layer inspection as and thus prevents the misclassification of the traffic.
If your custom application successfully matches the traffic, then no application override is needed.
Regards
07-29-2024 01:05 PM
Hi @Sarou22
Application override forcibly bypasses the AppID process and sets a session to match a manually configured Application name. Any sessions processed like this will not be scanned by parallel processing and will be offloaded to fastpath
For most use cases, we recommend creating a simple custom application with as few attributes as possible, as the app override will bypass scanning or signature detection. It will simply identify a session as the custom application and take no further action. This can be a very simple but powerful tool to help identify internal applications and improve throughput as the session is offloaded to hardware immediately, but please consider the security implications.
The following links explain with more details about Application Override
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRoCAK
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0
07-29-2024 01:54 PM
@Sarou22 Please read this
In general, you would use an application override policy if your custom application is not being correctly detected AND the PA is assigning the flow to a DIFFERENT built in application.
The application override then prevents the upper layer inspection as and thus prevents the misclassification of the traffic.
If your custom application successfully matches the traffic, then no application override is needed.
Regards
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!