These posts are helpful. I'll go into a bit more detail to see how others would go about it. We use EDI to send information to and from our mainframe with vendors. The EDI uses the AS2 application with Palo Alto detects. However our port is not in the list of default ports for the application. The default ports for this app are 80,443,4080,5443. We use TCP 5060. I was first thinking an application override policy and give a different port to the app, but based on the comments above that may not be such a good idea. I can see using ANY as the service, but that could potentially open other ports. In this case would it be better to use something like: For traffic coming from outside to inside to my EDI server, set the application to AS2. Since my port is 5060 do not use ANY but create a custom service for 5060. This way I am only allow AS2 on 5060 and nothing more? Would this be a better option?
... View more