- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-12-2022 08:09 AM
Hello,
I would need to write a policy to allow Oracle connection on specific servers.
Unfortunately I have some Oracle instances that don't use the standard TCP 1521 port.
How can I handle this problem writing just one rules that matches all my destination Oracle servers even if there are different port used?
Thanks for your reccomendations
Regards
01-12-2022 11:55 AM
You can create a rule (using your specific source/dest IPs and zones, add appID "oracle", then add in the specific service ports...
1. Add the app default port
2. Add in other non-standard ports for the app -OR- use a service group to hold all the custom service ports you create, and assign that group to the rule.
01-13-2022 12:25 AM
It is as @jbworley mentioned and there are articles from palo alto for such tasks:
How to Configure a Policy to Use a Range of Ports - Knowledge Base - Palo Alto Networks
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN44CAG
How to create a new service object - Knowledge Base - Palo Alto Networks
01-12-2022 11:55 AM
You can create a rule (using your specific source/dest IPs and zones, add appID "oracle", then add in the specific service ports...
1. Add the app default port
2. Add in other non-standard ports for the app -OR- use a service group to hold all the custom service ports you create, and assign that group to the rule.
01-13-2022 12:25 AM
It is as @jbworley mentioned and there are articles from palo alto for such tasks:
How to Configure a Policy to Use a Range of Ports - Knowledge Base - Palo Alto Networks
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN44CAG
How to create a new service object - Knowledge Base - Palo Alto Networks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!