<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PanOS 10.1.14-h2 - How does Palo identify if traffic belongs to an  'ms-update' application flow in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-1-14-h2-how-does-palo-identify-if-traffic-belongs-to-an/m-p/592323#M3425</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41506"&gt;@jebwilson&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The primary method PANW uses to identify applications is application signatures.&amp;nbsp; PANW does not reveal the specific details for each signature to my knowledge.&amp;nbsp; In some cases, protocol decoders and heuristics are used.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/app-id-overview" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/app-id-overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is an example where App-ID has identified the traffic as ssl, but also uses the certificate to change it to a different app.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVSCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVSCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enabling decryption will allow you to identify a lot more apps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2024 16:09:13 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-07-17T16:09:13Z</dc:date>
    <item>
      <title>PanOS 10.1.14-h2 - How does Palo identify if traffic belongs to an  'ms-update' application flow</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-1-14-h2-how-does-palo-identify-if-traffic-belongs-to-an/m-p/592313#M3424</link>
      <description>&lt;P&gt;I need to understand exactly makes a TCP flow identified as the 'ms-update' application. &lt;BR /&gt;&lt;BR /&gt;I found the Objects -&amp;gt; Applications -&amp;gt; ms-update app description. It shows the ports used, and other dependencies.&amp;nbsp;&amp;nbsp;But this does not explain exactly what makes one flow identified as the 'ms-update' application. And a second flow identified as some other application. &lt;BR /&gt;&lt;BR /&gt;Details on this topic would be appreciated.&amp;nbsp; Especially any info about specifically what parameters go into the decision to classify a flow as the 'ms-update' application.&amp;nbsp; Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 14:18:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-1-14-h2-how-does-palo-identify-if-traffic-belongs-to-an/m-p/592313#M3424</guid>
      <dc:creator>jebwilson</dc:creator>
      <dc:date>2024-07-17T14:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: PanOS 10.1.14-h2 - How does Palo identify if traffic belongs to an  'ms-update' application flow</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-1-14-h2-how-does-palo-identify-if-traffic-belongs-to-an/m-p/592323#M3425</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41506"&gt;@jebwilson&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The primary method PANW uses to identify applications is application signatures.&amp;nbsp; PANW does not reveal the specific details for each signature to my knowledge.&amp;nbsp; In some cases, protocol decoders and heuristics are used.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/app-id-overview" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/app-id-overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is an example where App-ID has identified the traffic as ssl, but also uses the certificate to change it to a different app.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVSCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVSCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enabling decryption will allow you to identify a lot more apps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 16:09:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-1-14-h2-how-does-palo-identify-if-traffic-belongs-to-an/m-p/592323#M3425</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-07-17T16:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: PanOS 10.1.14-h2 - How does Palo identify if traffic belongs to an  'ms-update' application flow</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-1-14-h2-how-does-palo-identify-if-traffic-belongs-to-an/m-p/592329#M3426</link>
      <description>&lt;P&gt;Thank you Tom.&amp;nbsp; Really appreciate the clear information and the quick reply!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 18:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-1-14-h2-how-does-palo-identify-if-traffic-belongs-to-an/m-p/592329#M3426</guid>
      <dc:creator>jebwilson</dc:creator>
      <dc:date>2024-07-17T18:54:44Z</dc:date>
    </item>
  </channel>
</rss>

