As we built out our Private Apps, we never leveraged the wildcard entry for domain for our corp environments (ex - *.randomco.com , *.corp.randomco.com) . While looking over community posts related to “npa” “wildcard” and documentation from our former NS engineer, I found a few mentions of leveraging the wildcard entry for access to PC’s, servers, RPD for support, streamlined PQDN access/connectivity.
That being said, I believe this will solve a lot of our headaches in terms of how granular some of our apps have become. We essentially had our ISFW admin do a 1-1 buildout of ISFW rules as a base for our Private App library.
What I need clarification or “best practice” on, though, handling the ports/protocols.
Do you typically go with a 1-65535 entry for TCP/UDP for this use-case?
Note: there are concerns internally that such a wildcard entry would create a sizable security hole.
NPA: Configuring Wildcard App Entry for Internal Resources
This topic has been closed for replies.
Sign up
Already have an account? Login
Sign in or register securely using Single Sign-On (SSO)
Employee Continue as Customer / Partner (Login or Create Account)Login to the community
Sign in or register securely using Single Sign-On (SSO)
Employee Continue as Customer / Partner (Login or Create Account)Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.



