- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-16-2018 06:55 AM
Am I correct in assuming that if you use App-ID you can't also use TCP sercice ports to allow aditiona other services on the same rule.
Thanks
Rob
02-16-2018 07:04 AM
Actually that works perfectly fine as long as the app-id is actually coming across on that service port; I have to do it quite often for SQL enviroments actually. You would simply set the app-id to whatever is desired, say ( mssql-db mssql-mon ) and then set the service to whatever you are using in your enviroment; just keep in mind that this will only work if the firewall is identifying that traffic as that application.
You could also create a custom app-id to match this traffic, or an application-override policy. This would allow you to maintain 'application-default' as the service depending on how much that matters to you.
02-16-2018 07:08 AM
I am aware you can override the port the app usualy uses.
But what if I have say two items one with an application and one without.
"SMTP (Application 25) - "
"Other (No Application) - Service TCP46"
My findings are that it breaks.
02-16-2018 07:18 AM
If you use app-id within the security policy and add a service that does not display that app-id it will break, as the traffic does not match the criteria of the rule. It doesn't really 'break', it's that the traffic doesn't actually match what is supplied by the security policy. If you are trying to pass traffic that doesn't map to an app-id (unknown-tcp or incomplete) you'll need to make a policy specifically for that traffic. Alternatively you could make a strict security policy that specifies an app-id of 'any' and then specify the service that needs to be allowed.
02-16-2018 07:40 AM
Thanks, Confirms my findings.
02-16-2018 08:14 AM
Hello @RobinClayton,
I too have run across these issues, what I end up doing is creating two rules. One that matches the app-id and one with no app-id and just a service port.
Cheers!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!