<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: traceroute application allows tcp port 80 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29397#M21466</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, I hope port 80 is added to allow web based traceroute e.g. &lt;A href="http://centralops.net/co/" title="http://centralops.net/co/"&gt;Free online network tools - traceroute, nslookup, dig, whois lookup, ping - IPv6&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Setting up security rule with service as 'application-default' should restrict allowed traffic with signature+port match only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Oct 2013 02:01:54 GMT</pubDate>
    <dc:creator>ukhapre</dc:creator>
    <dc:date>2013-10-30T02:01:54Z</dc:date>
    <item>
      <title>traceroute application allows tcp port 80</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29396#M21465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Received a call from a client said their external scanner shows their servers behind the firewall allows tcp port 80 connections and able to passive finger those servers, but there is no firewall rule permit tcp port 80 to those servers.&amp;nbsp; Digging it deeper, found one of the rule allows traceroute application with application default which allows icmp/dynamic, tcp/80, udp 33434-33534.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="9490" alt="Screen Shot 2013-10-28 at 5.48.47 PM.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9490_Screen Shot 2013-10-28 at 5.48.47 PM.png" /&gt;&lt;/P&gt;&lt;P&gt;I can understand icmp/dynamic and udp 33343-33534 portion, but why allow tcp port 80??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The interesting parts are,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; You can't use the traceroute as application and define your own services, since services in 5.0 does not support icmp.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; In most *nix system, you can customize traceroute to use any tcp/udp ports for probe, but why only permit tcp port 80?&amp;nbsp; Why not all tcp ports and udp ports?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are other client dealing with this issue?&amp;nbsp; What other applications have this similar issues that we have not discovery?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 00:59:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29396#M21465</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2013-10-29T00:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute application allows tcp port 80</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29397#M21466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, I hope port 80 is added to allow web based traceroute e.g. &lt;A href="http://centralops.net/co/" title="http://centralops.net/co/"&gt;Free online network tools - traceroute, nslookup, dig, whois lookup, ping - IPv6&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Setting up security rule with service as 'application-default' should restrict allowed traffic with signature+port match only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 02:01:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29397#M21466</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2013-10-30T02:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute application allows tcp port 80</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29398#M21467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tcptraceroute is sometimes used when icmp and udp is blocked.&lt;/P&gt;&lt;P&gt;Port 80 is open is most environments&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.catonmat.net/blog/tcp-traceroute/" title="http://www.catonmat.net/blog/tcp-traceroute/"&gt;http://www.catonmat.net/blog/tcp-traceroute/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Programm tcptraceroute uses TCP/80 as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.irongeek.com/i.php?page=backtrack-3-man/tcptraceroute" title="http://www.irongeek.com/i.php?page=backtrack-3-man/tcptraceroute"&gt;Manual Page - tcptraceroute(1)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 14:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29398#M21467</guid>
      <dc:creator>ExclusiveNetworksGermany</dc:creator>
      <dc:date>2013-10-30T14:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute application allows tcp port 80</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29399#M21468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;ukhapre wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hello, I hope port 80 is added to allow web based traceroute e.g. &lt;A class="jive-link-external-small" href="http://centralops.net/co/" rel="noreferrer"&gt;Free online network tools - traceroute, nslookup, dig, whois lookup, ping - IPv6&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Setting up security rule with service as 'application-default' should restrict allowed traffic with signature+port match only.&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Just keep this in mind, the first 8 packets will get pass the firewall until App-ID able identify the application,&amp;nbsp; that is plenty to perform passive finger printing to servers behind the firewall which may have tcp port 80 listen but you don't want the world to be able to probe it..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 15:05:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29399#M21468</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2013-10-30T15:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute application allows tcp port 80</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29400#M21469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But why limit to only TCP 80?&amp;nbsp; Why not TCP 443 or any tcp port?&amp;nbsp;&amp;nbsp; Since PAN firewall only support TCP or UDP as service,&amp;nbsp; you can't specific the service with the application.&amp;nbsp; The only way to lock it down is to use application default.&amp;nbsp; &lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;ExclusiveNetworksGermany wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;tcptraceroute is sometimes used when icmp and udp is blocked.&lt;/P&gt;
&lt;P&gt;Port 80 is open is most environments&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.catonmat.net/blog/tcp-traceroute/"&gt;http://www.catonmat.net/blog/tcp-traceroute/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The Programm tcptraceroute uses TCP/80 as well&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.irongeek.com/i.php?page=backtrack-3-man/tcptraceroute"&gt;Manual Page - tcptraceroute(1)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Marco&lt;/P&gt;
&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 15:07:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/29400#M21469</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2013-10-30T15:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute application allows tcp port 80</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/525353#M108645</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know this is an old post, but I found it as I have some odd traffic coming from an Android device, this was traceroute to the internet on port 80.&lt;/P&gt;
&lt;P&gt;A few apps were not working and the inclusion of this in the rule did help to fix one of them, just wanted to add that I found this article from Palo on the subject&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClrNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClrNCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 10:51:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traceroute-application-allows-tcp-port-80/m-p/525353#M108645</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2022-12-28T10:51:24Z</dc:date>
    </item>
  </channel>
</rss>

