Avaya ports Blocking

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Avaya ports Blocking

L1 Bithead

Hello,

 

We recently installed Avaya UCS and are currently using the Avaya Workplace application. For this setup, we configured the required security rules on our Palo Alto Networks PA-440 firewall. However, we are experiencing an issue when applying specific ports in the security policy.
We tested the following scenarios:
Could you please advise on the correct application and port requirements for the Avaya Workplace application.

 

Thanks

Satheesh

1 REPLY 1

Cyber Elite

Hi @SatheeshAnirudhan ,

 

Kudos to you for trying L7 rules!  That is the best practice.  As you have found, this can be very challenging.  The process that has worked very well for me is as follows:

 

  1. Create an application-based rule with application-default as the service.  This rule is your rule #2.
  2. Create an application-based rule with specific ports as the service because you cannot combine application-default and specific ports in the same rule.  This rule is used for applications that use non-standard ports.
  3. Create a catch-all rule to find anything that I missed.  This rule is your rule #1.

I put these 3 rules in order in the security policy.  The catch-all rule is used to identify the traffic that doesn't match the 1st 2 rules.  You can (1) mouse over the catch-all rule and use Log Viewer or you can use (2) Apps Seen column hyperlink to the Policy Optimizer to determine which traffic is not hitting the 1st 2 rules.  You modify rule 1 or 2 to include the new apps.  Repeat the process until you do not have any more hits on rule 3.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1144 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!