<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bittorent session identification in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18050#M13158</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done troubleshooting of the ghost sessions and I found this:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the bittorent and sip traffic come in from the Internet zone to Internet zone (the reason of this is still unknown)&lt;/LI&gt;&lt;LI&gt;I didn't find records into traffic monitor because there wasn't any security policy that matched and logged that traffic&lt;/LI&gt;&lt;LI&gt;although the policy wasn't set, the dashboard showed that applications on the top-app, because there was a bit of traffic from Trust Zone to Internet Zone and then, in that circumstance, sip and bittorrent were top-app.&lt;/LI&gt;&lt;LI&gt;ACC anyway didn't show any record of sip and bittorrent within that time period (none in&amp;nbsp; last-hour, none in last-day,...) : is this behaviour dependent on the enabled logging in the security policy ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you think about ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 10 Mar 2012 13:57:32 GMT</pubDate>
    <dc:creator>lauro7</dc:creator>
    <dc:date>2012-03-10T13:57:32Z</dc:date>
    <item>
      <title>Bittorent session identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18046#M13154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On PA-500 with PAN-OS 4.0.7, I have seen a session on dashboard-top application-last hour, but in corresponding ACC and in Monitor Traffic Log I don't find a record session. There is any reason ? Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2012 11:45:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18046#M13154</guid>
      <dc:creator>lauro7</dc:creator>
      <dc:date>2012-03-09T11:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Bittorent session identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18047#M13155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How did you search for it in the traffic log?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2012 23:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18047#M13155</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-09T23:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Bittorent session identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18048#M13156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I searched for it by a filter in traffic monitor as (app eq bittorrent). But today I found a similar problem with another app: &lt;STRONG&gt;sip&lt;/STRONG&gt;, with only 4 session displayed on top-appl on dashboard and no records in ACC and in traffic monitor. I attach some screenshots from dashboard, ACC and monitor traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Mar 2012 09:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18048#M13156</guid>
      <dc:creator>lauro7</dc:creator>
      <dc:date>2012-03-10T09:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Bittorent session identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18049#M13157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume you simply clicked on the sip area in the "top applications" in dashboard and ended up in the second screenshot?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My first thought then was that you would need to modify "Time" (which is currently Last Hour) but the top applications in dashboard is also regarding last hour so that shouldnt matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you verify that you in your security rules have enabled logging (this is made per security rule, you would also need to add a default deny in the end and configure that to log aswell since the "hidden" last rule (not visible in GUI) which does default deny have logging turned off)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a debug enable logging for both session start and session end (later in production you would normally just need logging on session end (if you want to keep logvolumes down) because then you get additional info such as session length and datavolume transmitted which session start lacks).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you need to have logging enabled in your security rules for the traffic to show up in the traffic log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However the ACC shouldnt be empty...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you have already verified that your PAN box have downloaded the latest app-db and such (and you also commited after the download)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also is it possible for you to update to latest 4.1.x (I think its currently 4.1.4 or so) just to rule out any known bugs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Mar 2012 09:48:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18049#M13157</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-10T09:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Bittorent session identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18050#M13158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done troubleshooting of the ghost sessions and I found this:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the bittorent and sip traffic come in from the Internet zone to Internet zone (the reason of this is still unknown)&lt;/LI&gt;&lt;LI&gt;I didn't find records into traffic monitor because there wasn't any security policy that matched and logged that traffic&lt;/LI&gt;&lt;LI&gt;although the policy wasn't set, the dashboard showed that applications on the top-app, because there was a bit of traffic from Trust Zone to Internet Zone and then, in that circumstance, sip and bittorrent were top-app.&lt;/LI&gt;&lt;LI&gt;ACC anyway didn't show any record of sip and bittorrent within that time period (none in&amp;nbsp; last-hour, none in last-day,...) : is this behaviour dependent on the enabled logging in the security policy ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you think about ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Mar 2012 13:57:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18050#M13158</guid>
      <dc:creator>lauro7</dc:creator>
      <dc:date>2012-03-10T13:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Bittorent session identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18051#M13159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You asked:&lt;/P&gt;&lt;P&gt;"is this behaviour dependent on the enabled logging in the security policy ?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer:&lt;/P&gt;&lt;P&gt;Yes, Just like URL filtering.. it cannot report upon something unless you are logging the traffic inside of a security policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if traffic same zone to same zone, it will also not report and will be allowed by default.. but you prob already knew that one.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 19:59:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bittorent-session-identification/m-p/18051#M13159</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-04-05T19:59:35Z</dc:date>
    </item>
  </channel>
</rss>

