<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom Application by destination address / port combination? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14388#M2439</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hi - R77.30&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Using custom applications, I don't see a way to identify an application by destination address and port combination. Is this not currently&amp;nbsp;supported in R77.30 / App control signature tool? I see there are various other ways to define but none that fit this particular case.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Apr 2018 13:37:22 GMT</pubDate>
    <dc:creator>Alex_Weldon</dc:creator>
    <dc:date>2018-04-11T13:37:22Z</dc:date>
    <item>
      <title>Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14388#M2439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hi - R77.30&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Using custom applications, I don't see a way to identify an application by destination address and port combination. Is this not currently&amp;nbsp;supported in R77.30 / App control signature tool? I see there are various other ways to define but none that fit this particular case.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 13:37:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14388#M2439</guid>
      <dc:creator>Alex_Weldon</dc:creator>
      <dc:date>2018-04-11T13:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14389#M2440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In R77.30 App Control this can be defined very easily:&lt;/P&gt;&lt;P&gt;- Application &amp;amp; URL Filtering &amp;gt; Applications/Sites &amp;gt; New&lt;/P&gt;&lt;P&gt;- type name for App (mySpecialSite) and click Next&lt;/P&gt;&lt;P&gt;- type IP (172.27.39.198:8080), click Add and click Next&lt;/P&gt;&lt;P&gt;- select Additional Categories and click Next&lt;/P&gt;&lt;P&gt;- click Finish&lt;/P&gt;&lt;P&gt;- use App in policy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 12:20:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14389#M2440</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-12T12:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14390#M2441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that, what about an address range? 172.27.39.0/24 lets say.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 12:23:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14390#M2441</guid>
      <dc:creator>Alex_Weldon</dc:creator>
      <dc:date>2018-04-12T12:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14391#M2442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;An address range is no site.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:43:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14391#M2442</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-12T13:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14392#M2443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;...but you could try a regular expression instead &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt; !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:49:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14392#M2443</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-12T13:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14393#M2444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, yeah I wasn't quite sure how to best address it. We have a few applications that reach out to a variety of address ranges with a defined port. But, they always show as unknown traffic wasn't sure if there was a solution for it in 77.30. Thank you for the suggestions though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 14:27:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14393#M2444</guid>
      <dc:creator>Alex_Weldon</dc:creator>
      <dc:date>2018-04-12T14:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14394#M2445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;However, I'm wondering if you would not prefer to just use a regular firewall rule for this (also full accelerated traffic) instead of an Application Control rule with just layer 4 information.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Apr 2018 16:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14394#M2445</guid>
      <dc:creator>Victor_MR</dc:creator>
      <dc:date>2018-04-21T16:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14395#M2446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "Services" column is hidden in the R77.30 App Control rulebase but can be shown by right-clicking on the section headings in the rule and selecting Service.&lt;/P&gt;&lt;P&gt;Now you can restrict the ports for any App Control rule, if you desire.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2018 04:55:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14395#M2446</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-22T04:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Application by destination address / port combination?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14396#M2447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks everyone for the suggestions. The rule is defined on the firewall side already with defined source, destination, and services. The issue I am trying to resolve is on the app control/url filtering side of things, all of the allowed known traffic is categorized as "Unknown Traffic" So we can sometimes have 1-2 gigs of "Unknown Traffic" even though it is a known and defined application which is what we were hoping we could define. I reached out to TAC who said they could create a custom application based on packet captures so I will provide them and see how it goes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 12:13:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Application-by-destination-address-port-combination/m-p/14396#M2447</guid>
      <dc:creator>Alex_Weldon</dc:creator>
      <dc:date>2018-04-23T12:13:48Z</dc:date>
    </item>
  </channel>
</rss>

