10-11-2020 12:17 AM
Hi Team,
I have a couple of questions in application vs services.
1. I have to permit a list of services for a particular traffic. In those list some of them are already in the applications like DNS, IMAP, Pop3 and I need to create some services with custom port. Now do I add these applications and the custom services in the same rule or does it have to be in two different rules ?
2. I need to permit bitdefender/kaspersky antivirus traffic. As per the application it uses only tcp 80/443 as standard port. But I do have a list of services which has custom ports like tcp 7075. Do i need to add as a service or add as an application and give any (instead of application-default) ?
Please advise.
10-11-2020 08:20 AM - edited 10-11-2020 08:21 AM
Hi,
1- You can add the application and all ports to same rule, as the application wont be identified based on the port it uses but here you will have to allow all services like also 53, 143...
2- you can choose the application and set service to any, that should work but not best practice.
10-12-2020 01:53 AM
Hi Abdul,
Thanks for your reply.
Now If I add applications for eg DNS, then do i need to allow 53 as well ? Then If I permit 53 in service and I need to permit some customer service like 7010, then I will be adding 7010 as well. WIll the application DNS be looking for service 7010 as well ? or how is the behavior ?
10-12-2020 03:09 AM
Hi @KrishnanR,
you will need to add all ports that the applications will use because in the services tab "Selected" will be set.
each application will use the ports it needed, DNS works on normally on Port 53, so it will use this port.
10-14-2020 12:33 AM
Thanks for your message.
If I have a list of applications like dns, https along with some services like TCP-7010(not related to dns or https), these applications have no relation with the services I am going to mention. So should it be in a single policy ?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!