<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow iOS Ring doorbell in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/211714#M241</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking for a proper way to allow the iOS Ring app to connect back to the video feed from an iOS device. Android phones work with no issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem&amp;nbsp;is that it&amp;nbsp;reports the web URL category as "unknown" which I am currently blocking.&lt;/P&gt;&lt;P&gt;I wrote my policy (below) to allow ssl traffic for all&amp;nbsp;unauthenticated users (mobile devices) to connect to the Ring IP address range, and assigned a new URL filtering policy that mirrors our current URL filtering policy, with the exception that "unknown" category is set to Alert instead of block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ring Policy.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14855iCDF2E15DE90FBC16/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Ring Policy.PNG" alt="Ring Policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a more proper way to do this?&lt;/P&gt;&lt;P&gt;The Ring ports are here:&amp;nbsp;&lt;A href="https://support.ring.com/hc/en-us/articles/205385394-What-Ports-Do-I-Need-to-Open-in-My-Firewall-for-Ring-Doorbells-and-Chimes-" target="_blank"&gt;https://support.ring.com/hc/en-us/articles/205385394-What-Ports-Do-I-Need-to-Open-in-My-Firewall-for-Ring-Doorbells-and-Chimes-&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Specifically the iOS ports&amp;nbsp;&lt;SPAN&gt;TCP out 80, 443, 5223, 15064 and&amp;nbsp;UDP out 53, 123, 18306 - 63919&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ring IP range:&amp;nbsp;35.174.122.0-35.174.123.255&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Apr 2018 15:02:45 GMT</pubDate>
    <dc:creator>SethArnoff</dc:creator>
    <dc:date>2018-04-25T15:02:45Z</dc:date>
    <item>
      <title>Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/211714#M241</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking for a proper way to allow the iOS Ring app to connect back to the video feed from an iOS device. Android phones work with no issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem&amp;nbsp;is that it&amp;nbsp;reports the web URL category as "unknown" which I am currently blocking.&lt;/P&gt;&lt;P&gt;I wrote my policy (below) to allow ssl traffic for all&amp;nbsp;unauthenticated users (mobile devices) to connect to the Ring IP address range, and assigned a new URL filtering policy that mirrors our current URL filtering policy, with the exception that "unknown" category is set to Alert instead of block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ring Policy.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14855iCDF2E15DE90FBC16/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Ring Policy.PNG" alt="Ring Policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a more proper way to do this?&lt;/P&gt;&lt;P&gt;The Ring ports are here:&amp;nbsp;&lt;A href="https://support.ring.com/hc/en-us/articles/205385394-What-Ports-Do-I-Need-to-Open-in-My-Firewall-for-Ring-Doorbells-and-Chimes-" target="_blank"&gt;https://support.ring.com/hc/en-us/articles/205385394-What-Ports-Do-I-Need-to-Open-in-My-Firewall-for-Ring-Doorbells-and-Chimes-&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Specifically the iOS ports&amp;nbsp;&lt;SPAN&gt;TCP out 80, 443, 5223, 15064 and&amp;nbsp;UDP out 53, 123, 18306 - 63919&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ring IP range:&amp;nbsp;35.174.122.0-35.174.123.255&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2018 15:02:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/211714#M241</guid>
      <dc:creator>SethArnoff</dc:creator>
      <dc:date>2018-04-25T15:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/223892#M259</link>
      <description>&lt;P&gt;All of the *.ring.com URLs are categorized as "business-and-economy" in my firewall.&amp;nbsp; Are you still having this issue?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jul 2018 20:19:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/223892#M259</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-07-28T20:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/224040#M260</link>
      <description>&lt;P&gt;If you know the URLS, and they are being categorized incorrectly, why not create a custom category for them and allow it?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 16:24:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/224040#M260</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-30T16:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/289604#M323</link>
      <description>&lt;P&gt;I know this is an older thread, but we are experiencing this issue as well.&amp;nbsp; All of the functionality within the Ring app works as far as we can tell except the live video feed.&amp;nbsp; The other Ring traffic hits URL Category: business-and-economy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The live video feed traffic is showing up in our URL filtering logs as category: unknown, and action is block-continue.&amp;nbsp; Unlike the rest of the Ring traffic, these requests are not resolving DNS, so the URL entry just shows an IP address:15064, so I don't have a list of URLs to add to a category.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts/ideas to get this to work without allowing unknown category?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 15:29:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/289604#M323</guid>
      <dc:creator>JoshFountaine</dc:creator>
      <dc:date>2019-09-23T15:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/298983#M331</link>
      <description>&lt;P&gt;I have the exact same problem with my 220.&amp;nbsp; Only way that I can get it to work is remove the Palo.&amp;nbsp; I have an any any rule and it still doesn't work.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2019 22:47:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/298983#M331</guid>
      <dc:creator>Rosenbusch</dc:creator>
      <dc:date>2019-11-16T22:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/301317#M333</link>
      <description>&lt;P&gt;I've had this issue for a while and have just looked into it further.&lt;/P&gt;&lt;P&gt;In our case I just changed the unknown category to alert.&lt;/P&gt;&lt;P&gt;However I understand that this might not be appropriate in all cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To keep the unknown URL category blocked, what you could do is create a rule above your web browsing policy to permit ssl on TCP/15064 to the internet, and on this rule have a URL filtering profile applied which permits unknown URLs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you wanted to make this more specific you could set up an external dynamic list for Amazon AWS using MineMeld and use that as the destination address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2019 02:11:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/301317#M333</guid>
      <dc:creator>jeremyw</dc:creator>
      <dc:date>2019-11-29T02:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/330045#M349</link>
      <description>&lt;P&gt;I know this is an old post, but I just ran into this problem as well. I have two Ring Cameras, one door bell cam and one stick-up cam in my backyard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of sudden, both cams stopped showing recorded images and the live feed didn't work.&lt;/P&gt;&lt;P&gt;I did get motion alerts, but when I tried to click on live view the image just never showed up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After some investigation, I found that RING was being stopped by threat prevention in the Palo.&lt;/P&gt;&lt;P&gt;In the logs it appeared that there were to instances of calls being made from the inside that hit the Threat policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Suspicious TLS Evasion Found on port 443 and&lt;/P&gt;&lt;P&gt;Microsoft Communicator INVITE Flood Denial of Service Vulnerability on port 15063&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both of which where informational.&lt;/P&gt;&lt;P&gt;To mitigate this I created a new Security Profile where I removed dropping packet that where on informational nature and added that to a policy that matched the predefined RING application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once that was done, all feeds and events came right back up.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 10:06:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/330045#M349</guid>
      <dc:creator>FrankJamesWilson</dc:creator>
      <dc:date>2020-05-27T10:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/456130#M413</link>
      <description>&lt;P&gt;Frank,&lt;/P&gt;&lt;P&gt;Thanks for posting your solution, but I am not clear on how you see it in the logs?&amp;nbsp; Which log were you seeing the threat?&amp;nbsp; I can not find any log details that match up with this.&amp;nbsp; Also, which security profile did you setup? I tried matching the Ring application and then just not having any security profile at all...&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 21:15:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/456130#M413</guid>
      <dc:creator>JohnSmock</dc:creator>
      <dc:date>2021-12-30T21:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Allow iOS Ring doorbell</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/469096#M423</link>
      <description>&lt;P&gt;After reading the article on ring, it doesnt specify but is required. TCP9002 for liveview on app.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 02:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/allow-ios-ring-doorbell/m-p/469096#M423</guid>
      <dc:creator>BenNoonan</dc:creator>
      <dc:date>2022-02-28T02:45:32Z</dc:date>
    </item>
  </channel>
</rss>

