<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The use of use-cache-for-identification introduced in PANOS 5.0.2? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14750#M10831</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the release note for PANOS 5.0.2 (released 2013-01-15):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;EM&gt;47195 – When the App-ID cache feature was enabled in previous releases (enabled by default), it was possible to pollute the cache to allow some applications to pass through the firewall, even when a rule was set to block the application. If you are running an older version of PAN-OS, you can disable the application cache by running set deviceconfig setting application cache no until you can upgrade. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;With this update, the App-ID cache will not be used in security policies by default. The following new CLI command has also been introduced to control whether or not the App-ID cache is used: set deviceconfig setting application use-cache-for-identification and is set to no by default. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;For more information, please refer to the Security Advisory PAN-SA-2013-0001 at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://securityadvisories.paloaltonetworks.com/"&gt;https://securityadvisories.paloaltonetworks.com/&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats the purpose of "use-cache-for-identification" compared to enable/disable app-id cache all together?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to comments in the security advisory found at &lt;A __default_attr="4315" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; the default of "no" for "use-cache-for-identification" in 5.0.2 seems to break things similar to how disabling app-id cache on its own would do (meaning some applications will be identified as unknown). While at the same time if you didnt disable app-id cache in 5.0.1 and update to 5.0.2 the app-id cache will remain active.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 19 Jan 2013 12:59:14 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-01-19T12:59:14Z</dc:date>
    <item>
      <title>The use of use-cache-for-identification introduced in PANOS 5.0.2?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14750#M10831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the release note for PANOS 5.0.2 (released 2013-01-15):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;EM&gt;47195 – When the App-ID cache feature was enabled in previous releases (enabled by default), it was possible to pollute the cache to allow some applications to pass through the firewall, even when a rule was set to block the application. If you are running an older version of PAN-OS, you can disable the application cache by running set deviceconfig setting application cache no until you can upgrade. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;With this update, the App-ID cache will not be used in security policies by default. The following new CLI command has also been introduced to control whether or not the App-ID cache is used: set deviceconfig setting application use-cache-for-identification and is set to no by default. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;For more information, please refer to the Security Advisory PAN-SA-2013-0001 at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://securityadvisories.paloaltonetworks.com/"&gt;https://securityadvisories.paloaltonetworks.com/&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats the purpose of "use-cache-for-identification" compared to enable/disable app-id cache all together?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to comments in the security advisory found at &lt;A __default_attr="4315" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; the default of "no" for "use-cache-for-identification" in 5.0.2 seems to break things similar to how disabling app-id cache on its own would do (meaning some applications will be identified as unknown). While at the same time if you didnt disable app-id cache in 5.0.1 and update to 5.0.2 the app-id cache will remain active.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2013 12:59:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14750#M10831</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-19T12:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: The use of use-cache-for-identification introduced in PANOS 5.0.2?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14751#M10832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mikand:&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Before 5.0.2:&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;set deviceconfig setting application cache no&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Completely disable Application Cache&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;set deviceconfig setting application cache yes (DEFAULT)&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Completely enable Application Cache for all applications&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;5.0.2 and Later:&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;set deviceconfig setting application cache no&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Completely disable Application Cache for all applications.&amp;nbsp; This impacts PBF and accuracy of heuristic apps (e.g. bittorrent)&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;set deviceconfig setting application cache yes (DEFAULT)&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Enable Application Cache.&amp;nbsp; See next two commands for Application Cache behavior&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;set deviceconfig setting application use-cache-for-identification no (DEFAULT)&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Application Cache only applies to certain applications that use it for proper App-ID (heuristics) and are not susceptible to poisoning (e.g. bittorrent)&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;set deviceconfig setting application use-cache-for-identification yes&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;EM style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Application Cache includes all applications (brings back old behavior)&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The new default settings should keep the benefits of the Application Cache (increased App-ID accuracy and PBF) without the cache poisoning risk. Our testing has shown that with normal enterprise traffic patterns there is no significant performance difference when the Application Cache is disabled ("&lt;STRONG&gt;set deviceconfig setting application cache no&lt;/STRONG&gt;" or "&lt;STRONG&gt;set deviceconfig setting application use-cache-for-identification no&lt;/STRONG&gt;")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2013 09:26:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14751#M10832</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2013-01-21T09:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: The use of use-cache-for-identification introduced in PANOS 5.0.2?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14752#M10833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2013 22:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14752#M10833</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-21T22:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: The use of use-cache-for-identification introduced in PANOS 5.0.2?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14753#M10834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anybody know what the commands are to view the current settings? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 16:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14753#M10834</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2013-08-15T16:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: The use of use-cache-for-identification introduced in PANOS 5.0.2?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14754#M10835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Quinton,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once we have made changes we can look at details on configure mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;samysu@SamySu# edit deviceconfig setting application&lt;/P&gt;&lt;P&gt;[edit deviceconfig setting application]&lt;/P&gt;&lt;P&gt;samysu@SamySu# show&lt;/P&gt;&lt;P&gt;application {&lt;/P&gt;&lt;P&gt;&amp;nbsp; notify-user yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; use-cache-for-identification no;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;[edit deviceconfig setting application]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 17:24:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14754#M10835</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-08-15T17:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: The use of use-cache-for-identification introduced in PANOS 5.0.2?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14755#M10836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Work perfect thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 18:09:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-use-of-use-cache-for-identification-introduced-in-panos-5-0/m-p/14755#M10836</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2013-08-15T18:09:38Z</dc:date>
    </item>
  </channel>
</rss>

