Clarification on Application and Service in security policy

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Clarification on Application and Service in security policy

L1 Bithead

Hi,

By restricting the security policy with specific application and allow ANY service leads to allow all traffic through that policy?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@IBM-MSS,

Yes, and also not really ... but also yes ... but primarily no 😀

 

What happens in that situation is that the firewall needs to allow enough traffic to pass to actually identify the application, so your rule will capture a whole lot more traffic than your actual intent. That being said, as soon as the firewall can identify the application and it isn't what you have specified the traffic will no longer match the rule and continue to be analyzed according to the rest of your security rulebase.

I'd generally recommend being heavily cautious when you're creating these sort of policies, and make them as restrictive as reasonably possible. You are allowing traffic to pass to identify the actual application, there's no way around that when creating a policy like this. 

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

@IBM-MSS,

Yes, and also not really ... but also yes ... but primarily no 😀

 

What happens in that situation is that the firewall needs to allow enough traffic to pass to actually identify the application, so your rule will capture a whole lot more traffic than your actual intent. That being said, as soon as the firewall can identify the application and it isn't what you have specified the traffic will no longer match the rule and continue to be analyzed according to the rest of your security rulebase.

I'd generally recommend being heavily cautious when you're creating these sort of policies, and make them as restrictive as reasonably possible. You are allowing traffic to pass to identify the actual application, there's no way around that when creating a policy like this. 

L1 Bithead

Thanks for the clarification.

During my investigation, i identified that telnet and netmap traffic is allowing through this policy. I believe this is because service will check on Layer 3 and Application will check on layer 7.

Cyber Elite
Cyber Elite

If you test connectivity with telnet then firewall sees TCP 3way handshake and as there is no application traffic yet it will be permitted.

You could set up some dummy rule to collect those incompletes and this avoids your app rule to match other traffic.

This example works well for that purpose as ping is not actually TCP application and it never matches to outgoing pings 🙂

 

Raido_Rattameister_0-1693499084673.png

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1 accepted solution
  • 822 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!