App-ID TSIDs provide previews to App-IDs and can be used to preview future App-IDs
before introducing them into your production network environment.
| Where Can I Use This? | What Do I Need? |
Prisma Access Next-Generation Firewall
|
This is a core Network Security feature for NGFWs and Prisma
Access; no prerequisites needed.
|
Palo Alto Networks provides a preview version of App-IDs to allow users to test and
validate modified and new App-IDs in the form of Threat Signature Indicators
(TSIDs). These TSIDs are delivered as vulnerability signatures using the category:
app-id-change and are, by default, configured on the
firewall with a severity level of Informational and an action
of Allow. The non-invasive setting provides monitoring
capabilities while preventing unwanted changes from blocking access to key
applications in a production environment.
The App-ID TSIDs are packaged with
Applications and Threats content updates
and include TSID entries for App-IDs that are slated for official release one month
later. For example, an App-ID TSID released in the first week of March will include
TSIDs for App-IDs that are scheduled for release in the first week of April. This
one month probationary period is to allow time for testing/validation and updates to
any security policies. You can refer to the Notices section of the
Applications
and Threats Content Release Notes for more details about the nature of the
TSIDs.
The name of the App-ID TSID (contained in the Threat ID/name field) correlates to the
name of the upcoming App-ID to