<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does &amp;quot;Unknown-udp&amp;quot; app allow any UDP Packets? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28758#M20992</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does "Unknown-udp" Appl. allow any UDP Packets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not find any app and would like to allow UDP only.&lt;/P&gt;&lt;P&gt;Roman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Sep 2014 11:36:32 GMT</pubDate>
    <dc:creator>rkra</dc:creator>
    <dc:date>2014-09-24T11:36:32Z</dc:date>
    <item>
      <title>Does "Unknown-udp" app allow any UDP Packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28758#M20992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does "Unknown-udp" Appl. allow any UDP Packets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not find any app and would like to allow UDP only.&lt;/P&gt;&lt;P&gt;Roman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 11:36:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28758#M20992</guid>
      <dc:creator>rkra</dc:creator>
      <dc:date>2014-09-24T11:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Does "Unknown-udp" app allow any UDP Packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28759#M20993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The app-id "unknown-udp" can be used to allow/block UDP traffic that did not match any other application signature. That does not mean all UDP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to allow all UDP traffic,you should create a service object containing the port range 1-65535.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 11:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28759#M20993</guid>
      <dc:creator>torm</dc:creator>
      <dc:date>2014-09-24T11:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Does "Unknown-udp" app allow any UDP Packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28760#M20994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Roman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case of any UDP based Application traffic, The PAN firewall will allow few packets in each direction &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;Client-Server and Server-Client) to identify/match the application signature App-ID. Ideally, it will be minimum 4 packets or 2000 bytes. Till that time, the PAN will identify that traffic as "Unknown-UDP" and allow it through. As soon as the application identified by PAN FW&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;the&amp;nbsp; appropriate policy/rule will be applied to that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference DOC:&lt;/P&gt;&lt;P&gt; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6139"&gt;How to Verify the Application Name Change from Unknown-tcp/udp to Actual App-ID&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/27272"&gt;unknown&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 12:01:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28760#M20994</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T12:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Does "Unknown-udp" app allow any UDP Packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28761#M20995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Roman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1416" data-externalid="" data-presence="null" data-userid="5160" data-username="torm" href="https://live.paloaltonetworks.com/people/torm" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;torm&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt; said, if you want to allow all UDP traffic, you may create a custom service profile and allow all applications in a "&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;security&lt;/SPAN&gt; Rule".&lt;/P&gt;&lt;P&gt;NOTE: UDP is not an application, it's a Transport layer protocol used to application traffic. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG alt="UDP-service.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15724_UDP-service.jpg" style="height: 449px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="UDP-service-policy.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15725_UDP-service-policy.jpg" style="height: 23px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 12:12:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28761#M20995</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T12:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Does "Unknown-udp" app allow any UDP Packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28762#M20996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi RKRA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When UDP packets hit firewall, firewall allows initial few UDP Packets. After that it may determine application based on packet content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes, firewall is not able to determine application because packets doesn't match existing decoder. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In such scenario firewall identifies stream as "unknown-udp".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You dont need to allow "unknown-udp" for any UDP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 13:09:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28762#M20996</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-24T13:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Does "Unknown-udp" app allow any UDP Packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28763#M20997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just FYI. All applications are not having Decoder. Hence, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; don't think it is not necessary to match decoder to identify an Application. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 13:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28763#M20997</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T13:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Does "Unknown-udp" app allow any UDP Packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28764#M20998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi HULK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By decoder I mean application signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 13:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28764#M20998</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-24T13:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does "Unknown-udp" app allow any UDP Packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28765#M20999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question to your answer is Yes. If you don't have a policy that is not denying "unknown-udp" application, firewall will allow it. In Monitor tab, you will source and destination address and application as "Unknown-UDP". It simply means firewall did not have signature for the packets it was seeing. You can also deny it by denying "unknown-udp" in security policy but is however configurable and is based on your requirement. Hope that helps. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 13:22:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-quot-unknown-udp-quot-app-allow-any-udp-packets/m-p/28765#M20999</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-09-24T13:22:49Z</dc:date>
    </item>
  </channel>
</rss>

