How to Configure APP-ID in Palo Alto | Detailed Explanation| LAB| DAY 42 |#PaloAltoTraining

preview_player
Показать описание

Hi Friends,

This video shows How to Configure APP-ID in Palo Alto with LAB and also with Detailed Explanation . If you like this video give it a thumps up and subscribe my channel for more video. Have any question or suggestion put it on comment
section.

Please follow me

Facebook group URL

Please find the link below for downloading images of network devices and EVE-ng file

#paloaltofirewalltraining #APP-ID #bikashtech
Рекомендации по теме
Комментарии
Автор

Hello Friends, Please Comment what you have learnt from this video. Share, Support, Subscribe!!!

BikashsTech
Автор

Thanks again, another thing learned from you!

Leader
Автор

At 17:18, the DNS traffic was allowed. As DNS is is UDP (in most cases) there's no FIN thus I suspect that is why it was aged-out. The "in-Out" policy to start with is wide open as long as the app is using default ports that traffic was good to go. Once you updated it to support only facebook, yup that killed any traffic other than facebook. The demo you were showing that DNS traffic should have landed on the interzone-default and thus that is where it would have been denied (not that it was aged out). Yes, adding DNS back to the appid and using application default fixed it. Keep your demo's up!

RyanBess
Автор

Great video to understand APP-ID of PA

faizankhan
Автор

Nice video dear, I want to know about custom app ID filtering.. how to block get, and post base requests for private app which are not included in Palo Alto app id.

Littlegujju-avengers
Автор

Hi Sir,
as we saw, google site was not opening, so can't add google application too in security policy as we did for facebook?

shwetankmishra
Автор

u share some interview Q&A for PA FW ?

vivektyagi
Автор

Can you please upload a troubleshooting video

akshayshahane
Автор

Hellow sir nice video
Sir last me aapne solution nhi bataya.
Please sir answer

himanshuyadav
Автор

Could you please explain how to block&unblock subtabs like facebook-chat. I did understand how the PA identify it, however I could see the way to block subtabs... thank you for your help

franciscoromero
Автор

Hi bro, APP-ID can block facebook-chat, facebook-video and etc. How does App-id knew these traffic is chat traffic, video traffic. In SSL/TLS, a connection between client and server is secured(encrypted) ?. How firewall can know if the traffice is secured ? ....

kaung
Автор

Bikash, how do you install pa-vm on eve-ng?

sonarsan
Автор

Can u please help me to sort out my query:

We currently do not do traffic decryption on the firewall for deep packet inspection. Can we safely consider converting eligible rules to application based rules even though we don't do any traffic decryption on the perimeter firewall? My concern is that since we don't decrypt traffic on the perimeter firewall we will not be able to accurately identify application traffic.

sai-icts
Автор

PA can block the tls traffic based on SNI in client hello packet or Common name field in certificate exchanged in server hello packet in case sni is not supported by web server.So my question is facebook is allowed and is encrypted .But if anyone try to access facebook chat, since application data is fully encrypted so how firewall can know without ssl decryption just on sni or cn field ?

DeepakKumar-ovko
Автор

When come migration Checkpoint to Paloalto

soumenchatterjee
Автор

How can I block mobile Facebook application in PA220

anilkrishnam
Автор

What is the difference between FQDN and URL

prashanthkumar