<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: App-ID Windows Remote Management Showing Up As Web-Browsing in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-app-id-windows-remote-management-showing-up/ta-p/514477</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;I data-stringify-type="italic"&gt;This article is based on a discussion,&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/app-id-windows-remote-managment-showing-as-web-browsing/td-p/488232" target="_blank" rel="noopener"&gt;App-ID Windows Remote Management Showing Up As Web-Browsing&lt;/A&gt;,&lt;/SPAN&gt;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;posted by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5588"&gt;@Gun-Slinger&lt;/a&gt;&amp;nbsp;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;and answered by the Support Team.&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;Read on to see the discussion and solution!&lt;/I&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;We recently upgraded to 10.1.5-h1 and it appears after the upgrade the Windows-Remote-Management traffic over tcp5985 is now being identified as Web-browsing. This is causing that traffic to drop. We checked dynamic updates and presently leveraging the latest update released on 5/16. Seeing if this is a growing issue?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Solution:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Closing the loop on this issue. After working with TAC there is a known issue that is resolved in the 10.1.6 code released yesterday. The issue is when a policy uses L7 app-id with specific ports configured in the service port field as opposed to using "application-default". I took the workaround I used and changed it to application-default, removed the specific tcp ports listed, and removed web-browsing; leaving just windows-remote-management. This resolved the issue and will plan on an upgrade in the near future to 10.1.6.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 09 Sep 2022 21:35:10 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2022-09-09T21:35:10Z</dc:date>
    <item>
      <title>Nominated Discussion: App-ID Windows Remote Management Showing Up As Web-Browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-app-id-windows-remote-management-showing-up/ta-p/514477</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;I data-stringify-type="italic"&gt;This article is based on a discussion,&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/app-id-windows-remote-managment-showing-as-web-browsing/td-p/488232" target="_blank" rel="noopener"&gt;App-ID Windows Remote Management Showing Up As Web-Browsing&lt;/A&gt;,&lt;/SPAN&gt;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;posted by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5588"&gt;@Gun-Slinger&lt;/a&gt;&amp;nbsp;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;and answered by the Support Team.&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;Read on to see the discussion and solution!&lt;/I&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;We recently upgraded to 10.1.5-h1 and it appears after the upgrade the Windows-Remote-Management traffic over tcp5985 is now being identified as Web-browsing. This is causing that traffic to drop. We checked dynamic updates and presently leveraging the latest update released on 5/16. Seeing if this is a growing issue?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Solution:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Closing the loop on this issue. After working with TAC there is a known issue that is resolved in the 10.1.6 code released yesterday. The issue is when a policy uses L7 app-id with specific ports configured in the service port field as opposed to using "application-default". I took the workaround I used and changed it to application-default, removed the specific tcp ports listed, and removed web-browsing; leaving just windows-remote-management. This resolved the issue and will plan on an upgrade in the near future to 10.1.6.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 09 Sep 2022 21:35:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-app-id-windows-remote-management-showing-up/ta-p/514477</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2022-09-09T21:35:10Z</dc:date>
    </item>
  </channel>
</rss>

