<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Facebook working as application reddit-base in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/facebook-working-as-application-reddit-base/m-p/1227249#M5817</link>
    <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your message.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As more web-based applications are developed and refined, the useage of SSL forward proxy decryption rules may be needed.&lt;BR /&gt;For example, the FW can easily recognize facebook-base, however of the 10 to 15 sub/child applications under facebook (facebook-post, facebook-chat, facebook-video, facebook-filesharing, etc), these applications may not be seen, as the traffic is still encapsulated packet.&amp;nbsp; This would be why certain FB applications would still be allowed.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As for facebook-base showing up as reddit-base, certainly does not sound correct for a L7 application signature based firewall.&lt;/P&gt;
&lt;P&gt;You may want to consider opening a TAC case, so they can review/revise the application signatures as needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2025 17:12:43 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2025-04-23T17:12:43Z</dc:date>
    <item>
      <title>Facebook working as application reddit-base</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/facebook-working-as-application-reddit-base/m-p/1224239#M5705</link>
      <description>&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;We are currently experiencing an issue with URL filtering and application-based policies. We’ve set up a policy to block the Facebook application, but it’s still being allowed through. In the logs, it shows as the application "Application reddit-base" instead of Facebook.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;When we remove the block rule, Facebook-related apps function normally, but when the rule is applied, it allows the traffic as the "reddit-base" application and hits a different rule.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Has anyone encountered a similar issue? We’ve tried both the latest and previous app-IDs and even rolled back, but the issue persists.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Any suggestions or insights would be greatly appreciated!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 21:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/facebook-working-as-application-reddit-base/m-p/1224239#M5705</guid>
      <dc:creator>Jagdeep1</dc:creator>
      <dc:date>2025-03-19T21:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook working as application reddit-base</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/facebook-working-as-application-reddit-base/m-p/1227249#M5817</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your message.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As more web-based applications are developed and refined, the useage of SSL forward proxy decryption rules may be needed.&lt;BR /&gt;For example, the FW can easily recognize facebook-base, however of the 10 to 15 sub/child applications under facebook (facebook-post, facebook-chat, facebook-video, facebook-filesharing, etc), these applications may not be seen, as the traffic is still encapsulated packet.&amp;nbsp; This would be why certain FB applications would still be allowed.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As for facebook-base showing up as reddit-base, certainly does not sound correct for a L7 application signature based firewall.&lt;/P&gt;
&lt;P&gt;You may want to consider opening a TAC case, so they can review/revise the application signatures as needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 17:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/facebook-working-as-application-reddit-base/m-p/1227249#M5817</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2025-04-23T17:12:43Z</dc:date>
    </item>
  </channel>
</rss>

