<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL traffic mis-identified as TOR in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-traffic-mis-identified-as-tor/m-p/14779#M10856</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This could be due to either&amp;nbsp; caching of the IP + dest Port&amp;nbsp; for app: &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Bittorrent and TOR&lt;/SPAN&gt; or session prediction .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1&amp;gt;Check the traffic Logs for Dest:74.125.24.155and destination-port 443 to see if any SSL application was seen.&amp;lt;&amp;lt;--To gauge if there was any SSL sent to this destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2&amp;gt; Check if there are any Predict sessions:&lt;/P&gt;&lt;P&gt;&amp;gt;show session all filter destination 74.125.24.155 destination-port 443 type predict&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3&amp;gt;To clear the prediction:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;gt;clear session all filter destination 74.125.24.155 destination-port 443 type predict&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;4&amp;gt;Check the status of &lt;/SPAN&gt;appid&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; cache.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show running application setting&lt;/P&gt;&lt;P&gt;Application setting:&lt;/P&gt;&lt;P&gt;==&amp;gt;Application cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;5&amp;gt;If the app cache is yes, Try turning&amp;nbsp; off the app cache :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; set application cache no&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;optional:To turn on&amp;nbsp; app-cache &lt;/P&gt;&lt;P&gt;&amp;gt; set application cache no&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Let me know if this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 May 2013 22:08:20 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2013-05-27T22:08:20Z</dc:date>
    <item>
      <title>SSL traffic mis-identified as TOR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-traffic-mis-identified-as-tor/m-p/14777#M10854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seeing over the last few days traffic going from our users (various different users in different locations) to IP addresses in Google's range (74.125.0.0/16) being identified as TOR, and subsequently blocked - traffic is all dest port 443.&amp;nbsp; This is preventing access to certain websites hosted on Google's platform - appspot.com for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume Google is not running TOR nodes, and looking back over previous release notes I see PAN-OS has had trouble identifying TOR in the past.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(irrelevant fields removed):&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Session ID&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 3133462&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Type&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; deny&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Action&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; deny&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Application&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; tor&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Rule&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; Bittorrent and TOR&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Category&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; web-advertisements&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;IP Protocol&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; tcp&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Bytes&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 2,665&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Bytes Received&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 2,119&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Bytes Sent&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 546&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Repeat Count&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Packets&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 9&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Packets Received&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Packets Sent&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Source address&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; x.x.x.x&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Source Port&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 1342&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Source Zone&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; trust&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Destination address&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 74.125.24.155&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Destination Country&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; US&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Destination Port&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; 443&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Destination Zone&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; untrust&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone else seen this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Liam.LL&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 May 2013 14:29:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-traffic-mis-identified-as-tor/m-p/14777#M10854</guid>
      <dc:creator>LCMember2860</dc:creator>
      <dc:date>2013-05-27T14:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSL traffic mis-identified as TOR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-traffic-mis-identified-as-tor/m-p/14778#M10855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a&amp;nbsp; Tor Brouser and usually used to&lt;SPAN style="color: #444444; font-family: arial, sans-serif; font-size: small; background-color: #ffffff;"&gt; safely browse the Internet. (anonymity over 443 port)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 May 2013 21:50:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-traffic-mis-identified-as-tor/m-p/14778#M10855</guid>
      <dc:creator>Oleksandr</dc:creator>
      <dc:date>2013-05-27T21:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL traffic mis-identified as TOR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-traffic-mis-identified-as-tor/m-p/14779#M10856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This could be due to either&amp;nbsp; caching of the IP + dest Port&amp;nbsp; for app: &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Bittorrent and TOR&lt;/SPAN&gt; or session prediction .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1&amp;gt;Check the traffic Logs for Dest:74.125.24.155and destination-port 443 to see if any SSL application was seen.&amp;lt;&amp;lt;--To gauge if there was any SSL sent to this destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2&amp;gt; Check if there are any Predict sessions:&lt;/P&gt;&lt;P&gt;&amp;gt;show session all filter destination 74.125.24.155 destination-port 443 type predict&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3&amp;gt;To clear the prediction:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;gt;clear session all filter destination 74.125.24.155 destination-port 443 type predict&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;4&amp;gt;Check the status of &lt;/SPAN&gt;appid&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; cache.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show running application setting&lt;/P&gt;&lt;P&gt;Application setting:&lt;/P&gt;&lt;P&gt;==&amp;gt;Application cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;5&amp;gt;If the app cache is yes, Try turning&amp;nbsp; off the app cache :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; set application cache no&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;optional:To turn on&amp;nbsp; app-cache &lt;/P&gt;&lt;P&gt;&amp;gt; set application cache no&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Let me know if this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 May 2013 22:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-traffic-mis-identified-as-tor/m-p/14779#M10856</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-05-27T22:08:20Z</dc:date>
    </item>
  </channel>
</rss>

