<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bypassing app-ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27514#M20055</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that's my taught's also, to deploy SSL decryption policy...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks guys...!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Jan 2015 09:37:36 GMT</pubDate>
    <dc:creator>Tician</dc:creator>
    <dc:date>2015-01-07T09:37:36Z</dc:date>
    <item>
      <title>Bypassing app-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27511#M20052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recently I deploy outbound policies to filter inside traffic to Internet, but I noticed that some application bypassing app-ID filter. Just to clarify my setup I allow some application to go out (dns, web-browsing, ssl...and couple more..) service default. In that pool isn't youtube and teamviewer, but somehow they went out bypassing explicit application filter. When I filter session browser by DNS addresses of youtube servers, I found that all streaming was flowing like SSL traffic which is allowed by policy. &lt;/P&gt;&lt;P&gt;For TeamViewer I can't catch how he went out, in explicit deny policy I filter logs and see that teamviewer was denied until 10:00AM, but after that time I'm using him without problem...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tician &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2015 10:14:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27511#M20052</guid>
      <dc:creator>Tician</dc:creator>
      <dc:date>2015-01-06T10:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing app-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27512#M20053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tician,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TeamViewer also uses SSL. You would need SSL decrypt in order to block it using app-id.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Guillermo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2015 10:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27512#M20053</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2015-01-06T10:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing app-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27513#M20054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tician,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above statement is correct. To fully utilize the App-ID inspection for SSL traffic, it has to be decrypted via the decryption policy. Otherwise how can we see what it inside the SSL traffic, besides source and destination?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2015 18:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27513#M20054</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-01-06T18:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing app-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27514#M20055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that's my taught's also, to deploy SSL decryption policy...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks guys...!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2015 09:37:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27514#M20055</guid>
      <dc:creator>Tician</dc:creator>
      <dc:date>2015-01-07T09:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing app-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27515#M20056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please do not forget to mark this thread as 'Answered' or mark any 'Helpful' answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2015 17:13:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27515#M20056</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-01-07T17:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing app-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27516#M20057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;another option is to create a custom app-id that can identify the ssl certs (common name &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are many options such as SSL-Req-Certificate , ssl-req-client-hello, ssl-rsp-cert-subjectpublickey, ssl-rsp-certicate, ssl-rsp-server-hello etc.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will be more of a brute force approach blocking anything that matches the SSL SNI (Server name indication) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example to block Adap.tv (advertisement) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user a custom pattern-match with context ssl-req-client-hello with a regex&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;.\.adap.\tv&lt;/STRONG&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this will match the client hello for any character going to .adap.tv for sites that use wildcards may be a bit more difficult but then you can block the entire &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many of the built in apps also identify ssl applications such as facebook-video even though its not decrypted. &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2015 20:37:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27516#M20057</guid>
      <dc:creator>jkim2</dc:creator>
      <dc:date>2015-01-07T20:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing app-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27517#M20058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, this can work for some, but with websites certain websites, like Youtube, this would not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Youtube is classified as google.com without SSL decryption and listed under the search-engines because of the certificate CN being listed as *.google.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With no SSL decryption, we can't differentiate between the two (Youtube and Google). &lt;/P&gt;&lt;P&gt;I understand this is not always the case, but it is something to consider. Instead of creating custom applications, it may be easier to just go ahead and perform SSL decryption. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2015 22:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27517#M20058</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-01-07T22:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing app-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27518#M20059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;similar to the youtube thread. .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;if you create an app-id it'll take precedence over the built in apps &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;similar to if you create custom apps that are categorized as web-browsing they'll match the custom one &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2015 15:04:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-app-id/m-p/27518#M20059</guid>
      <dc:creator>jkim2</dc:creator>
      <dc:date>2015-01-08T15:04:55Z</dc:date>
    </item>
  </channel>
</rss>

