<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create custom App-ID signature for specific unknown traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29816#M21790</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Peter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you considered using Application Override? This is the simplest solution if you can define an application based on IP address and port number.&amp;nbsp; If you truely require a signature you will need sniffer captures and some evaluation of the first few packets. If you are lucky you will see some string like "User Agent = NMAP"&amp;nbsp; and use this as your identifier. Some applications will be moredifficult to identify. You will not know until you look as the captures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your last option isto ask Paloalto to create a new Application and submit the request to....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.paloaltonetworks.com/researchcenter/submit-an-application/"&gt;http://www.paloaltonetworks.com/researchcenter/submit-an-application/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Jun 2011 22:45:26 GMT</pubDate>
    <dc:creator>skrall</dc:creator>
    <dc:date>2011-06-16T22:45:26Z</dc:date>
    <item>
      <title>Create custom App-ID signature for specific unknown traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29815#M21789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good afternoon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A considerable amount of traffic to/from our Akamai servers is not recognized by our PA-4060s running v3.1.9. We would like to create a custom App-ID signature that would identify all traffic to/from our Akamai servers (based on /28 subnet) as: &lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;SU Akamai&lt;/STRONG&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; akamai-11-053.syr.edu (here we’ll use 128.230.11.48/28)&lt;BR /&gt;Destination: a72-247-124-182.deploy.akamaitechnologies.com&lt;BR /&gt;From Port:&amp;nbsp;&amp;nbsp; 12347&lt;BR /&gt;To Port:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65453&lt;BR /&gt;Protocol:&amp;nbsp;&amp;nbsp;&amp;nbsp; udp&lt;BR /&gt;Application: insufficient-data&lt;BR /&gt;Action:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; allow&lt;BR /&gt;Rule:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit datacenter to all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would appreciate any tips for creating custom App-ID signatures!&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Respectfully,&lt;/P&gt;&lt;P&gt;Peter Rounds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 17:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29815#M21789</guid>
      <dc:creator>phrounds</dc:creator>
      <dc:date>2011-06-16T17:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create custom App-ID signature for specific unknown traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29816#M21790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Peter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you considered using Application Override? This is the simplest solution if you can define an application based on IP address and port number.&amp;nbsp; If you truely require a signature you will need sniffer captures and some evaluation of the first few packets. If you are lucky you will see some string like "User Agent = NMAP"&amp;nbsp; and use this as your identifier. Some applications will be moredifficult to identify. You will not know until you look as the captures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your last option isto ask Paloalto to create a new Application and submit the request to....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.paloaltonetworks.com/researchcenter/submit-an-application/"&gt;http://www.paloaltonetworks.com/researchcenter/submit-an-application/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 22:45:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29816#M21790</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-06-16T22:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Create custom App-ID signature for specific unknown traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29817#M21791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Steve!&lt;/P&gt;&lt;P&gt;Does application override cause traffic that is "overrided" to disappear from monitoring?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Respectfully,&lt;/P&gt;&lt;P&gt;Peter ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 14:32:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29817#M21791</guid>
      <dc:creator>phrounds</dc:creator>
      <dc:date>2011-06-17T14:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Create custom App-ID signature for specific unknown traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29818#M21792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No. Override has 2 steps.&lt;/P&gt;&lt;P&gt;1) Create a simple Application identified simply by dest port or protocol.&lt;/P&gt;&lt;P&gt;2) Create an App Override rule that defines zones and IPs&amp;nbsp; and Port and then the "Name" of&amp;nbsp; the application that this traffic should receive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And traffic conforming to the AppOR rule that you defined in step 2 gets classified/Named the Application you created in step 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;App OR is typically used for the following reasons.&lt;/P&gt;&lt;P&gt;1) Assign an app name to some custom/home grown application or tcp/udp Unknown traffic that Paloalto is detecting.&lt;/P&gt;&lt;P&gt;2) Turn off deep packet inspection for performance reasons.&lt;/P&gt;&lt;P&gt;3) Testing to verify that Deep Packet inspection is not the reason for some performance problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One common example is SIP.&amp;nbsp; SIP phones put the IP address of the phone in the Payload.&amp;nbsp; SIP gateways like the Paloalto, when doing NAT, should change the source IP address in the IP header and should modify the IP address in the payload. Sometimes the modification done by the SIP gateway are incompatible with the requirements of the PBX. By creating an App OR for Port 5060 we turn off the deep packet inspection and modification and only do NAT. This is a common workaround for SIP issues using AppOR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 17:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-custom-app-id-signature-for-specific-unknown-traffic/m-p/29818#M21792</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-06-17T17:07:44Z</dc:date>
    </item>
  </channel>
</rss>

