<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uknown-tcp in application based policy logs !! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2780#M2076</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The user guide is wrong. We can get that cleaned up. The application you are overriding to (custom or otherwise) should have a value specified as the default port. This is what "app-default" will use. Alternatively, you should put the specific port you want in the Service column. Otherwise, the system will allow traffic on other ports until it determines if it matches the specified app. For the override to work properly, the port in the override rule should match the port in the default port field of the app or a port explicitly configured in the service column.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Jul 2010 16:20:55 GMT</pubDate>
    <dc:creator>mjacobsen</dc:creator>
    <dc:date>2010-07-23T16:20:55Z</dc:date>
    <item>
      <title>Uknown-tcp in application based policy logs !!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2775#M2071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'am using PAN-OS 3.0.9, and i have configured some policies in witch i allow some applications defined by application override. I noticed that in the logs associated to this policies, there are lines that are identified as "unknown-tcp" with action :"allow" and type "end", is this normal?&lt;/P&gt;&lt;P&gt;Normaly the firewall should not allow this connexions because they are not part of the application override, and should only allow this applications.&lt;/P&gt;&lt;P&gt;Any explanations please.&lt;/P&gt;&lt;P&gt;Regard's.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jul 2010 12:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2775#M2071</guid>
      <dc:creator>asia</dc:creator>
      <dc:date>2010-07-19T12:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Uknown-tcp in application based policy logs !!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2776#M2072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If there is traffic that is coming through the paloalto device that was not caught by the application override, that indicates that your application override rule does not include the criteria for for this traffic...i.e port, source/destination ip, etc.&lt;/P&gt;&lt;P&gt;Also if you are seeing sessions in the traffic log for unknowtcp, that same log tells you the specific rule that is allowing this traffic.&lt;/P&gt;&lt;P&gt;Also make sure that you do not have an allow all rule some where in your rule set that covers criteria that your application override rule does not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you,&lt;/P&gt;&lt;P&gt;Stephen Whyte&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jul 2010 21:01:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2776#M2072</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-07-19T21:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Uknown-tcp in application based policy logs !!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2777#M2073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my case, the logs mention the same rule that allows the applications defined by application override. Normaly, the rule must allow only the ports/ip mentioned in the application override rule. And there is not other rule that allow the traffic marked as unknown-tcp.&lt;/P&gt;&lt;P&gt;Any other idea please?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jul 2010 11:29:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2777#M2073</guid>
      <dc:creator>asia</dc:creator>
      <dc:date>2010-07-20T11:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Uknown-tcp in application based policy logs !!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2778#M2074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What ports are being allowed in the service column of the security rule? Can you provide a little more detail on the override rule and security rule configuration as well as the details of the unknown traffic (particularly the destination port).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jul 2010 15:07:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2778#M2074</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-07-20T15:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Uknown-tcp in application based policy logs !!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2779#M2075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the service column i allow "any" service, in the admin guide it is recommended to not use "use application default" for user defined applications. The destination ports marked as Unknown-tcp are various (internal developement applications) and different from those defined in the application default ports definition and those defined in the application override rule.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Jul 2010 08:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2779#M2075</guid>
      <dc:creator>asia</dc:creator>
      <dc:date>2010-07-21T08:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Uknown-tcp in application based policy logs !!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2780#M2076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The user guide is wrong. We can get that cleaned up. The application you are overriding to (custom or otherwise) should have a value specified as the default port. This is what "app-default" will use. Alternatively, you should put the specific port you want in the Service column. Otherwise, the system will allow traffic on other ports until it determines if it matches the specified app. For the override to work properly, the port in the override rule should match the port in the default port field of the app or a port explicitly configured in the service column.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Jul 2010 16:20:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uknown-tcp-in-application-based-policy-logs/m-p/2780#M2076</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-07-23T16:20:55Z</dc:date>
    </item>
  </channel>
</rss>

