<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identifying unknown-tcp in Monitor tab in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23972#M17470</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For traffic like iSCSI your best bet is to get this into a segregated vlan that does not transit routers and firewalls if at all possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it must transit the PA, create an application override to improve performance and insure there is a little latency as possible on this traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Apr 2015 01:20:45 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2015-04-17T01:20:45Z</dc:date>
    <item>
      <title>Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23960#M17458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a PA-3020 running 6.0.3.&amp;nbsp; Basically we have iSCSI replication set up between two sites.&amp;nbsp; When I pull up the traffic in the Monitor tab I see the picture below.&amp;nbsp; Even though iSCSI traffic is defined in the Applications section I tried creating another app to identify it but still see the "unknown-tcp" traffic show up.&amp;nbsp; Is there something I am missing or is it not possible to change what it pulls up in Monitor?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="iscsi.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14777_iscsi.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2014 18:48:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23960#M17458</guid>
      <dc:creator>ClintL</dc:creator>
      <dc:date>2014-07-30T18:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23961#M17459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A reference DOC for this&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; :&lt;/SPAN&gt; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1549"&gt;Incomplete, Insufficient data and Not-applicable in the application field&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2014 19:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23961#M17459</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-30T19:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23962#M17460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way though to tell the Palo that any unknown-tcp traffic on port 3260 from specific zones will be classified as iSCSI?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2014 21:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23962#M17460</guid>
      <dc:creator>ClintL</dc:creator>
      <dc:date>2014-07-30T21:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23963#M17461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Custom app signature&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2015"&gt;Custom Application Signatures&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2014 21:42:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23963#M17461</guid>
      <dc:creator>j.liu</dc:creator>
      <dc:date>2014-07-30T21:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23964#M17462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Clint,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;J.&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;liu&lt;/SPAN&gt; said, you need to configure a custom application signature to identify traffic on port &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;3260. Secondly, need a security policy in place&amp;nbsp; from specific zones to allow that traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2014 21:49:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23964#M17462</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-30T21:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23965#M17463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For iSCSI, I would be using an application override, essentially fast-pathing it which is what you would want to do with low-latency traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CNSE Study Guide page 34 gives the config steps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2014 00:15:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23965#M17463</guid>
      <dc:creator>RichardThornton</dc:creator>
      <dc:date>2014-07-31T00:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23966#M17464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Clint, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, the default application &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;iSCSI&lt;/SPAN&gt; is using TCP 3260. Then, why you want to use a custom app for this..?&amp;nbsp; Better, you should use the previously mentioned DOC to get the exact reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2014 02:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23966#M17464</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-31T02:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23967#M17465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Honestly I don't know why it is not identifying the traffic as iSCSI.&amp;nbsp; It might be something proprietary with the vendor that is preventing the Palo from recognizing it even though it is coming across on 3260.&amp;nbsp; I just want to be able to see in the reports that it is iSCSI.&amp;nbsp; I will most likely end up programming both solutions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answers, guys.&amp;nbsp; I'll give it a try today.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2014 12:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23967#M17465</guid>
      <dc:creator>ClintL</dc:creator>
      <dc:date>2014-07-31T12:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23968#M17466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&amp;nbsp; Clint,&lt;/P&gt;&lt;P&gt;According to the screenshot you have attached here, it looks like the amount of data transferred between the Server and client is very low &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;few KB). PAN firewall &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;need&lt;/SPAN&gt; at least 2000 Bytes of application data or minimum 4 packets to identify an application signature correctly. So, could you please check how many packets has been exchanged through those sessions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="session-magnifying glass.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14792_session-magnifying glass.jpg" style="height: 49px; width: 620px;" /&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;IMG alt="session-rx-tx-count.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14793_session-rx-tx-count.jpg" style="height: 254px; width: 620px;" /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;Insufficient data in the application field&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Insufficient data means that there was not enough data to identify the application. So for example, if the 3-way TCP handshake completed and there was one data packet after the &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;handshake but&lt;/SPAN&gt; that one data packet was not enough to match any of our signatures, you would see insufficient data in the application field of the traffic log.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2014 17:18:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23968#M17466</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-31T17:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23969#M17467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think there is something proprietary going on.&amp;nbsp; I created a custom app signature with tcp/3260, created an allow rule and the traffic stopped transmitting altogether but I wasn't getting any deny entries.&amp;nbsp; I'm just guessing but maybe when it isn't let through as is the Palo possibly strips out whatever proprietary info the data has and makes it unreadable to the iSCSI equipment on the other side.&amp;nbsp; I haven't tried the application override rule yet though.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="iscsi2.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14794_iscsi2.png" style="height: 378px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2014 18:45:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23969#M17467</guid>
      <dc:creator>ClintL</dc:creator>
      <dc:date>2014-07-31T18:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23970#M17468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Clint,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's looks like the firewall passing a good amount of traffic, but still not able to identify the correct application-signature. Do you have a chance to take a packet capture. We can relay that PCAP through a&amp;nbsp; LINUX REPLAY server and let you know if you need to contact with PAN support to open an App-ID BUG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the mean time, you may also try app-override once.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2014 19:53:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23970#M17468</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-31T19:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23971#M17469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever get this one resolved?&amp;nbsp; I have a newly configured PA-500 and noticed the same issue for our iSCSI traffic. It is a Dell EqualLogic. There is already a Application ID for iscsi for tcp/3260; however in our QoS reports it is shown as unknown-tcp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Apr 2015 21:31:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23971#M17469</guid>
      <dc:creator>jharlow</dc:creator>
      <dc:date>2015-04-15T21:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23972#M17470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For traffic like iSCSI your best bet is to get this into a segregated vlan that does not transit routers and firewalls if at all possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it must transit the PA, create an application override to improve performance and insure there is a little latency as possible on this traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2015 01:20:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23972#M17470</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-04-17T01:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying unknown-tcp in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23973#M17471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;iSCSI traffic has been segregated into its own network (own switch); however, we do send bits over our firewall/routers for replication. The traffic is coming and going between our network here and our offsite location.&amp;nbsp; As one could imagine, this data is appearing in all of the reports and typically on the top5 due to the about of bits being sent offsite (for DR). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Apr 2015 15:52:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identifying-unknown-tcp-in-monitor-tab/m-p/23973#M17471</guid>
      <dc:creator>jharlow</dc:creator>
      <dc:date>2015-04-23T15:52:28Z</dc:date>
    </item>
  </channel>
</rss>

