L7 Inspection

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

L7 Inspection

L2 Linker

Hi All,

 

i migrated my asa to paloalto , but i can see that all policies are assigned service port but not appliation , so how can i get benefit from from application field ?

 

how can i transfer all polices from l4 to l7

4 REPLIES 4

L6 Presenter

Hi,

 

You can specify application  based on your current ports and set in the service tab an "application-default" or "any" (less secure)  option/field:

 

APP.PNG

Cyber Elite
Cyber Elite

@NetworkGeek to actually transfer the l4 to l7 you would need to do it more or less manually; there is no way to guarentee that a specified service actually means a given applicaiton, so those will not automatically switch over. 

did you convert manually or via the migration utility? either way, the migration utility actually has a path to assist for migrating from port based to app based by importing logs back into it and analyzing the traffic and making suggestions that you can agree to or customize.

 

you should also be comfortable with the idea of application shift. traffic that starts out as web-proxy more often than not changes to another app, so just something to consider depending on your approach (whitelisting and implicit deny vs blacklisting and explicit allow).

 

I come from an ASA background and I can tell you while there are some basic similiarities, the two are worlds apart.

--
CCNA Security, PCNSE7

@bradk14 I always forget about the updated migration tool. I only used it a few times  years back and it kinda blew so I've just kinda ignored it. Even at "worlds apart" it might kind of be an understatement, the thought process of administering an ASA doesn't easily switch to the PAN world. 

  • 2757 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!