<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question regarding Signal messaging application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227150#M124078</link>
    <description>&lt;P&gt;Thanks for the feedback. I didn't understand why I was seeing the UDP/dynamic traffic drops when making a phone call.&amp;nbsp; The call does go through, but I was surprised to the this traffic in the logs.&amp;nbsp; If I'm just sending text only, the logs are showing the SSL/443 traffic which makes sense.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Apr 2025 18:07:35 GMT</pubDate>
    <dc:creator>shoot0267</dc:creator>
    <dc:date>2025-04-22T18:07:35Z</dc:date>
    <item>
      <title>Question regarding Signal messaging application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1226844#M124039</link>
      <description>&lt;P&gt;Currently have a PA-440 at home and trying to setup Signal messaging application.&amp;nbsp; I know the application is cert-pinned and therefore cannot be decrypted.&amp;nbsp; To get it to work, I added to the SSL Exclusion Decryption list the following hosts/domains per the Signal website:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.signal.org/hc/en-us/articles/360007320291-Firewall-and-Internet-settings" target="_blank"&gt;https://support.signal.org/hc/en-us/articles/360007320291-Firewall-and-Internet-settings&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*.signal.org&lt;/P&gt;
&lt;P&gt;signal.art&lt;/P&gt;
&lt;P&gt;signal.group&lt;/P&gt;
&lt;P&gt;signal.link&lt;/P&gt;
&lt;P&gt;signal.me&lt;/P&gt;
&lt;P&gt;signal.tube&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Text messaging and calling works, but the only application I’m seeing in the logs are SSL/443.&amp;nbsp; I don’t see signal-base or signal-file-transfer applications in the logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I make a call from my iphone, I see in the logs UDP/dynamic ports are getting dropped.&amp;nbsp; Some of random dynamic UDP ports are identified as STUN traffic, and others are “not applicable”. I thought this traffic was supposed to be covered with the signal-base application.&lt;/P&gt;
&lt;P&gt;In my security policy, signal-base, signal-file-transfer and SSL are included in my overall trusted outbound rule.&amp;nbsp; I do have STUN application added too but all are set to application-default.&lt;/P&gt;
&lt;P&gt;Is this normal behavior for the signal application?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 14:52:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1226844#M124039</guid>
      <dc:creator>shoot0267</dc:creator>
      <dc:date>2025-04-17T14:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding Signal messaging application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227138#M124072</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What you are seeing is correct. Since the decryption is not happening, the PAN cannot determine the proper application, hence just ssl/443.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 16:26:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227138#M124072</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-22T16:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding Signal messaging application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227149#M124077</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What you are seeing is correct. Since the decryption is not happening, the PAN cannot determine the proper application, hence just ssl/443.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I would agree, but then why would Palo have APP-IDs for signal other than the base if decryption is needed, yet decryption for signal isn't a viable option?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:07:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227149#M124077</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-04-22T18:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding Signal messaging application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227150#M124078</link>
      <description>&lt;P&gt;Thanks for the feedback. I didn't understand why I was seeing the UDP/dynamic traffic drops when making a phone call.&amp;nbsp; The call does go through, but I was surprised to the this traffic in the logs.&amp;nbsp; If I'm just sending text only, the logs are showing the SSL/443 traffic which makes sense.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:07:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227150#M124078</guid>
      <dc:creator>shoot0267</dc:creator>
      <dc:date>2025-04-22T18:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding Signal messaging application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227151#M124079</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139131"&gt;@shoot0267&lt;/a&gt;&amp;nbsp;-- You shouldn't need decryption for things like "base" apps to show up.&amp;nbsp; Even undecrypted traffic the SNI is seen, and "signal-base" should be showing up in traffic logs.&amp;nbsp; There's probably an issue with legit signal traffic not matching the app-id correctly, it's probably best to open a support case so the app-id matches.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:25:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227151#M124079</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-04-22T18:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding Signal messaging application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227153#M124080</link>
      <description>&lt;P&gt;Yeah, I'm not decrypting any of the Signal traffic.&amp;nbsp; About a month ago, I did see in my logs app-id "signal-file-transfer" but never saw "signal-base".&amp;nbsp; Now, I'm only seeing SSL/443 for chat messages.&amp;nbsp; I guess the Signal application on the iphone may have changed.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:48:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-signal-messaging-application/m-p/1227153#M124080</guid>
      <dc:creator>shoot0267</dc:creator>
      <dc:date>2025-04-22T18:48:05Z</dc:date>
    </item>
  </channel>
</rss>

