How Security Policy works with Combination of Application vs Services ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How Security Policy works with Combination of Application vs Services ?

L0 Member

Hi Experts , 

 

We have existing rule for "Syslog" application ,our current security polcy with App-id and services configured as below ,

 

Application - "Syslog" ( default application which allows TCP 1468,  TCP 1514, TCP 6514, UDP 514 and UDP 1514 ) 

Service        -  "application-default"

 

Now we have a requirement to additionally add TCP-514 and UDP-6514 to this rule .

 

So my question here is do I need to only add TCP-514 and UDP-6514 under services instead of application-default and this means  you only need to add the ports to the service group that are not covered under the default app port list .  or 

 

I need to add (TCP 1468,  TCP 1514, TCP 6514, UDP 514 and UDP 1514)   + additional 2 ports TCP-514 & UDP-6514 ?

 

How this will work . Can someone please explain me . 

 

Note : I don't want to allow "Any" port - We need more secure option for achieving the end goal by adding the

the required services in the Service field rather than using Any.

 

Regards , 

Chethan 

 

 

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello,

This can be accomplished two ways.

1. One policy that has the application syslog and you specify the ports/services

2. two policies first one is application syslog and default services/ports, and the second one would be application syslog with the ports that you need that are missing from the default.

 

Remember that the firewall reads policies top down then left to right. so everything needs to match prior to the firewall applying that policy.

 

example:

 

If you have a policy that is application syslog and default services, but you need tcp/514, this policy will NOT apply. If you have a policy application syslog and you specify port tcp/514, the firewall will only allow syslog identified traffic over port tcp/514.

 

Hope that makes sense.

I want in one rule . I don't want to create 2 different rules . So I do i need to add all the service ports which are already there in Application Syslog + Additional ports TCP-514 and UDP-6514 .

  • 4451 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!