03-01-2013 11:18 AM
Dears,
I am working on a migration from Check Point to Palo Alto. We used that PA Migration Tool for CP rules into PA.
The main problem is all CP rules are based on services and we want to transform them into PA applications... BUT, the PA apps tool (applipedia) doesnt show the apps by ports...
SOmetimes is hard to uderstand the name of PA applications... and also we would like to know if there is a method to find PA application using ports numbers...
for example:
what is the PA Application name for service using TCP 5757 ?
right now we are searching on internet those aplications then relating with PA apps...
is there any easy way easy to do that ?
thanks in advance!!
03-01-2013 11:34 AM
https://play.google.com/store/apps/details?id=ch.sourcenet.applipedia
Type 5757 and it will spit out:
msn-file-transfer
among other info:
Default ports: tcp/443, tcp/1863, tcp/1025-65535, udp/1025-65535
So I guess there is some API available to do these kind of searches...
Edit: Seems to be a custom API because a search for "tcp/5757" ends up with a http request for:
03-01-2013 11:30 AM
If there exits an application based on the port,you can find it using applipedia by simply typing the port number.
03-01-2013 11:32 AM
Navigate to monitor tab --traffic logs click on a port number and edit it, press enter you will see all applications for that port number.
03-01-2013 11:34 AM
https://play.google.com/store/apps/details?id=ch.sourcenet.applipedia
Type 5757 and it will spit out:
msn-file-transfer
among other info:
Default ports: tcp/443, tcp/1863, tcp/1025-65535, udp/1025-65535
So I guess there is some API available to do these kind of searches...
Edit: Seems to be a custom API because a search for "tcp/5757" ends up with a http request for:
03-02-2013 03:20 PM
One approach you might want to consider is to create the PA rules with services (ports) first like they were in Checkpoint. Then as you see what applications are going out on the appropriate rule, you add the application to a duplicate rule above the services (ports) only rule. Based on the size add complexity of your rule base this may be an option. We had a lot of special rules on our Checkpoint rule base to address applications that used the non-standard ports. These are the ones that were easily converted to Application based rules with service as "any". I am assuming you are doing a in-place replacement as opposed to inline deployment followed by removal of checkpoint.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!