<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ms-rdp and cotp in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ms-rdp-and-cotp/m-p/573169#M2444</link>
    <description>&lt;P&gt;Thank you for your reply. That explains what we are seeing here. In one of our old networks we're seeing just rdp and it still works, altoogh now I am tempted to find out, if we have any rdp issues that couldn't be explained.&lt;/P&gt;
&lt;P&gt;In our newest integration we're just bulding our policies and saw cotp alongside rdp and it was not something I expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jan 2024 11:35:54 GMT</pubDate>
    <dc:creator>janhoppe</dc:creator>
    <dc:date>2024-01-16T11:35:54Z</dc:date>
    <item>
      <title>ms-rdp and cotp</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ms-rdp-and-cotp/m-p/573165#M2442</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have googled and searched the community but I am still at a loss: why is the "rdp" communication identified as "cotp" sometimes? Does anyone have an answer or a a link?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great no-unplanned-downtime-day everyone!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 10:55:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ms-rdp-and-cotp/m-p/573165#M2442</guid>
      <dc:creator>janhoppe</dc:creator>
      <dc:date>2024-01-16T10:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: ms-rdp and cotp</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ms-rdp-and-cotp/m-p/573166#M2443</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317775"&gt;@janhoppe&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Generally you see this more when someone has log-start enabled on RDP policies (which is a good practice in my eye since you likely&amp;nbsp;&lt;EM&gt;want&amp;nbsp;&lt;/EM&gt;fast indication that someone has an RDP window open when looking at logs without having to go into the session table).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you see this in the logs when that isn't the case it simply means that the firewall hasn't properly identified it under the ms-rdp application. That&amp;nbsp;&lt;EM&gt;shouldn't&amp;nbsp;&lt;/EM&gt;be that much of an issue since ms-rdp implicitly utilizes cotp and t.120 as the underlying technology that drives ms-rdp, however I know a lot of people simply include ms-rdp and cotp in the same entries since that false-negative on the ms-rdp signature&amp;nbsp;&lt;EM&gt;can&amp;nbsp;&lt;/EM&gt;cause connection issues for folks if it doesn't switch over properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As to&amp;nbsp;&lt;EM&gt;why&amp;nbsp;&lt;/EM&gt;that happens, it's just because the firewall didn't see the proper traffic to match the ms-rdp signature properly. That could be because some packets dropped along the way that prevent it from being identified properly, it could be because the service on the endpoint wasn't operating properly and therefore didn't return traffic as expected, or a number of other issues.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 11:27:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ms-rdp-and-cotp/m-p/573166#M2443</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-01-16T11:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: ms-rdp and cotp</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ms-rdp-and-cotp/m-p/573169#M2444</link>
      <description>&lt;P&gt;Thank you for your reply. That explains what we are seeing here. In one of our old networks we're seeing just rdp and it still works, altoogh now I am tempted to find out, if we have any rdp issues that couldn't be explained.&lt;/P&gt;
&lt;P&gt;In our newest integration we're just bulding our policies and saw cotp alongside rdp and it was not something I expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 11:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ms-rdp-and-cotp/m-p/573169#M2444</guid>
      <dc:creator>janhoppe</dc:creator>
      <dc:date>2024-01-16T11:35:54Z</dc:date>
    </item>
  </channel>
</rss>

