<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Classify ARD? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18341#M13373</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;Remote Desktop Protocol (RDP) is a multi-channel protocol that allows a user to connect to a networked computer. Clients exist for most versions of Windows (including handheld versions), Linux/Unix, Mac OS X and other modern operating systems. The server listens by default on TCP port 3389. Microsoft refers to the official RDP server software as Terminal Services or Remote Desktop Services. The official client software is referred to as either Remote Desktop Connection (RDC) or Terminal Services Client (TSC). Mac OS X's client is called Apple Remote Desktop (ARD).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this for the description for MS-RDP but I can't figure out if thats what I use to classify ARD or not. The ports don't look correct and currently I don't have a way to test the traffic. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Dec 2011 23:17:42 GMT</pubDate>
    <dc:creator>rob.burgoyne</dc:creator>
    <dc:date>2011-12-29T23:17:42Z</dc:date>
    <item>
      <title>Classify ARD?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18341#M13373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;Remote Desktop Protocol (RDP) is a multi-channel protocol that allows a user to connect to a networked computer. Clients exist for most versions of Windows (including handheld versions), Linux/Unix, Mac OS X and other modern operating systems. The server listens by default on TCP port 3389. Microsoft refers to the official RDP server software as Terminal Services or Remote Desktop Services. The official client software is referred to as either Remote Desktop Connection (RDC) or Terminal Services Client (TSC). Mac OS X's client is called Apple Remote Desktop (ARD).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this for the description for MS-RDP but I can't figure out if thats what I use to classify ARD or not. The ports don't look correct and currently I don't have a way to test the traffic. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Dec 2011 23:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18341#M13373</guid>
      <dc:creator>rob.burgoyne</dc:creator>
      <dc:date>2011-12-29T23:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Classify ARD?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18342#M13374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you perform a packet capture using Wireshark on this data?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you contacted technical support at Apple for more information about ARD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jared&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Dec 2011 01:31:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18342#M13374</guid>
      <dc:creator>jdavis</dc:creator>
      <dc:date>2011-12-30T01:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Classify ARD?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18343#M13375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apple remote desktop seems like a pretty widely used application. I really hope palo alto has this in their app-id database... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Dec 2011 01:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18343#M13375</guid>
      <dc:creator>rob.burgoyne</dc:creator>
      <dc:date>2011-12-30T01:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Classify ARD?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18344#M13376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can check whether there is an Application ID signature for a particular application in the Palo Alto Networks Applipedia (&lt;A href="http://apps.paloaltonetworks.com/applipedia//"&gt;http://apps.paloaltonetworks.com/applipedia//&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can submit a request to have an Application ID signature developed at this URL:&amp;nbsp; &lt;A class="active_link" href="http://www.paloaltonetworks.com/researchcenter/submit-an-application/"&gt;http://www.paloaltonetworks.com/researchcenter/submit-an-application/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears that ARD falls under the "ms-rdp" application according to Applipedia.&amp;nbsp; If ARD is not being identified by a security policy that has the "ms-rdp" application I recommend the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Perform a packet capture to obtain the Layer-4 port(s) used by ARD.&lt;/LI&gt;&lt;LI&gt;Contact Apple technical support to obtain further information about the protocol.&lt;/LI&gt;&lt;LI&gt;Open a technical support case with Palo Alto Networks.&amp;nbsp; Provide the information gathered in steps 1 and 2.&amp;nbsp; They can help you determine whether ARD is being identified as "ms-rdp" or not.&amp;nbsp; A bug can be opened requesting that application signature that includes ARD be updated for inclusion in an upcoming "Apps &amp;amp; Threats" content release.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jared&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Dec 2011 02:29:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/classify-ard/m-p/18344#M13376</guid>
      <dc:creator>jdavis</dc:creator>
      <dc:date>2011-12-30T02:29:13Z</dc:date>
    </item>
  </channel>
</rss>

