<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Torrent in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26488#M19334</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I'm not mistaken there hasn't been any update regarding bittorrent these past few weeks. I tried relaying this to PAN but what we did was just take the other app that bittorrent uses and put it on the block list. that way we are able to control bittorrent again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Nov 2013 04:54:34 GMT</pubDate>
    <dc:creator>HartkentlyNua</dc:creator>
    <dc:date>2013-11-08T04:54:34Z</dc:date>
    <item>
      <title>Torrent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26484#M19330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have anyone of you noticed something regarding torrent(bittorrent, transmission..etc..)?&lt;/P&gt;&lt;P&gt;We received a report that a torrent app which is&lt;STRONG&gt; transmission&lt;/STRONG&gt; is able to evade the app detection of Palo Alto NGFW.&lt;/P&gt;&lt;P&gt;I tested it in my lab, I use Bittorrent and I saw that it can really breach Palo Alto NGFW and successfully downloaded a file.&lt;/P&gt;&lt;P&gt;We traced the logs and sessions, we noticed that these torrent is using other app such as teredo, unknown-tcp, and unknown-udp.&lt;/P&gt;&lt;P&gt;I don't know if this has happened before but its new to me. We are expecting that if we block bittorrent, we dont have to block other apps, Isn't that how it should work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hartkently&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 08:16:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26484#M19330</guid>
      <dc:creator>HartkentlyNua</dc:creator>
      <dc:date>2013-11-07T08:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: Torrent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26485#M19331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Harkently,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What content version is your PAN firewall running on ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 16:27:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26485#M19331</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-07T16:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Torrent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26486#M19332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Torrent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the application was not identified properly there are couple things which may have happened&lt;/P&gt;&lt;P&gt;&amp;gt; The application would have changed their signature which is not updated on PAN apps content yet&lt;/P&gt;&lt;P&gt;&amp;gt; There may be an issue in identifying the app because bittorent opens predict session and tries to map the child sessions as the traffic flows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any further clear analysis it would be nice to take flow basics and packet captures to understand what was the traffic and how the PAN analysed the apps to narrow down the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 00:39:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26486#M19332</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-11-08T00:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Torrent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26487#M19333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kunal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;currently the content version is 404-2015, I believed that is the latest update..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hartkently&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 04:52:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26487#M19333</guid>
      <dc:creator>HartkentlyNua</dc:creator>
      <dc:date>2013-11-08T04:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Torrent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26488#M19334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I'm not mistaken there hasn't been any update regarding bittorrent these past few weeks. I tried relaying this to PAN but what we did was just take the other app that bittorrent uses and put it on the block list. that way we are able to control bittorrent again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 04:54:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/torrent/m-p/26488#M19334</guid>
      <dc:creator>HartkentlyNua</dc:creator>
      <dc:date>2013-11-08T04:54:34Z</dc:date>
    </item>
  </channel>
</rss>

