Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Mastering Palo Alto Networks - Second Edition

You're reading from  Mastering Palo Alto Networks - Second Edition

Product type Book
Published in Jun 2022
Publisher Packt
ISBN-13 9781803241418
Pages 636 pages
Edition 2nd Edition
Languages
Concepts
Author (1):
Tom Piens aka Piens aka 'reaper' Tom Piens aka Piens aka 'reaper'
Profile icon Tom Piens aka Piens aka 'reaper'

Table of Contents (18) Chapters

Preface 1. Understanding the Core Technologies 2. Setting Up a New Device 3. Building Strong Policies 4. Taking Control of Sessions 5. Services and Operational Modes 6. Identifying Users and Controlling Access 7. Managing Firewalls through Panorama 8. Upgrading Firewalls and Panorama 9. Logging and Reporting 10. Virtual Private Networks 11. Advanced Protection 12. Troubleshooting Common Session Issues 13. A Deep Dive into Troubleshooting 14. Cloud-Based Firewall Deployment 15. Supporting Tools 16. Other Books You May Enjoy
17. Index

Custom applications and threats

Every once in a while, an application may not be known. This could be due to it being a new application that has not been used much in the wild or could be something a developer created in-house for which it is not reasonable to expect there to be signatures to identify the session.

In these cases, it is possible to create custom applications that use custom signatures and can trigger an App-ID to positively identify the previously unknown application.

The need for a custom application usually starts with the discovery of an abnormality in the traffic log. In the following screenshot, I have discovered my solar power converter, and an IoT device is communicating with its home server over an unknown-tcp connection:

Figure 10.12 – An unknown-tcp application in the traffic log

Figure 11.1: An unknown-tcp application in the traffic log

There are two ways to address this issue:

  • Implement an application override that forcibly sets all these sessions to a specific application
  • Create...
lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}