<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Striking a Balance Between Control and Protection</title>
	<atom:link href="http://www.paloaltonetworks.com/researchcenter/2009/05/striking-a-balance-between-control-and-protection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.paloaltonetworks.com/researchcenter/2009/05/striking-a-balance-between-control-and-protection/</link>
	<description>The Palo Alto Networks Research Center Blog</description>
	<lastBuildDate>Mon, 04 Apr 2011 14:46:14 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Firewall 2.0 &#187; The Case for Application Enablement</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/05/striking-a-balance-between-control-and-protection/comment-page-1/#comment-455</link>
		<dc:creator>Firewall 2.0 &#187; The Case for Application Enablement</dc:creator>
		<pubDate>Fri, 10 Jul 2009 20:36:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=224#comment-455</guid>
		<description>[...] As we have said before, the days of blocking applications that might not be “approved” are gone. These applications are here to stay. The applications themselves are not risks, but make no mistake, they can introduce risks and as such, need to be secured right along side Oracle, SAP, SharePoint and other business applications. [...]</description>
		<content:encoded><![CDATA[<p>[...] As we have said before, the days of blocking applications that might not be “approved” are gone. These applications are here to stay. The applications themselves are not risks, but make no mistake, they can introduce risks and as such, need to be secured right along side Oracle, SAP, SharePoint and other business applications. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mkeil</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/05/striking-a-balance-between-control-and-protection/comment-page-1/#comment-454</link>
		<dc:creator>mkeil</dc:creator>
		<pubDate>Wed, 17 Jun 2009 00:22:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=224#comment-454</guid>
		<description>&lt;a href=&quot;#comment-1896&quot; rel=&quot;nofollow&quot;&gt;@Bryan&lt;/a&gt;
we monitor the state of the sessions so we know which is which and only when that state changes do we re-apply the policy.</description>
		<content:encoded><![CDATA[<p><a href="#comment-1896" rel="nofollow">@Bryan</a><br />
we monitor the state of the sessions so we know which is which and only when that state changes do we re-apply the policy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bryan</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/05/striking-a-balance-between-control-and-protection/comment-page-1/#comment-453</link>
		<dc:creator>Bryan</dc:creator>
		<pubDate>Tue, 16 Jun 2009 03:26:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=224#comment-453</guid>
		<description>Hi, Matt
I have one question about Application identification in Palo Alto networks products that is there any risk of leaking packet due to app identification? For example, the first packet has been identified as App X and along with others information this traffic matched policy 1# with allow action. So the 1st packet passed through the firewall. Then the second packet comes in firewall and being identified as App Y and it supposed may match policy 2# with deny action. So looks the 1st packet leaked to wrong destination which might be dropped at first time. Is it right? Thanks for your any feedback!

-Bryan</description>
		<content:encoded><![CDATA[<p>Hi, Matt<br />
I have one question about Application identification in Palo Alto networks products that is there any risk of leaking packet due to app identification? For example, the first packet has been identified as App X and along with others information this traffic matched policy 1# with allow action. So the 1st packet passed through the firewall. Then the second packet comes in firewall and being identified as App Y and it supposed may match policy 2# with deny action. So looks the 1st packet leaked to wrong destination which might be dropped at first time. Is it right? Thanks for your any feedback!</p>
<p>-Bryan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JaneRadriges</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/05/striking-a-balance-between-control-and-protection/comment-page-1/#comment-452</link>
		<dc:creator>JaneRadriges</dc:creator>
		<pubDate>Sat, 13 Jun 2009 17:59:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=224#comment-452</guid>
		<description>Great post! I&#039;ll subscribe right now wth my feedreader software!</description>
		<content:encoded><![CDATA[<p>Great post! I&#8217;ll subscribe right now wth my feedreader software!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

