<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: gotoassist application recognition in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33005#M24191</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's indeed how our rules are setup:&lt;/P&gt;&lt;P&gt;We use an application group to allow several remote support applications, service application-default&lt;/P&gt;&lt;P&gt;For these applications, no user-id required (user: any)&lt;/P&gt;&lt;P&gt;from zone trust to zone untrust&lt;/P&gt;&lt;P&gt;Basic security profile applied, but that should not block legitimate traffic (will check in threat log)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I do notice, is some traffic gets recognized as citrix-jedi and gotomeeting, those are very similar to gotomeeting. And they are allowed too.&lt;/P&gt;&lt;P&gt;Threre's really no clear line to draw. It's one of those apps that use generic ports randomly, to many different ip's randomly ... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Dec 2013 16:57:18 GMT</pubDate>
    <dc:creator>dieter_b</dc:creator>
    <dc:date>2013-12-19T16:57:18Z</dc:date>
    <item>
      <title>gotoassist application recognition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33003#M24189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is anyone else having issues with PA not recognizing gotoassist very well ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Citrix documentation expects you to open tons of DNS addresses and/or IP ranges, but I'm a bit wary of opening ALL traffic on ports 80 and 443 to these (most IP ranges are on Amazon btw) since we're heavily relying on application identification.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:22:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33003#M24189</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-12-19T16:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: gotoassist application recognition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33004#M24190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dieterb,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Citrix software gotoassist works on the ports 80/443. If the services are made "App default" it uses the ports needed to have the gotoassist traffic allowed. Now in the apps column since we have added gotoassist it looks for signature pattern of gotoassit with combination of ports needed. If this combination matches only then traffic is allowed. If just ports match and signature pattern is not allowed the traffic should not be permitted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:39:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33004#M24190</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-12-19T16:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: gotoassist application recognition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33005#M24191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's indeed how our rules are setup:&lt;/P&gt;&lt;P&gt;We use an application group to allow several remote support applications, service application-default&lt;/P&gt;&lt;P&gt;For these applications, no user-id required (user: any)&lt;/P&gt;&lt;P&gt;from zone trust to zone untrust&lt;/P&gt;&lt;P&gt;Basic security profile applied, but that should not block legitimate traffic (will check in threat log)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I do notice, is some traffic gets recognized as citrix-jedi and gotomeeting, those are very similar to gotomeeting. And they are allowed too.&lt;/P&gt;&lt;P&gt;Threre's really no clear line to draw. It's one of those apps that use generic ports randomly, to many different ip's randomly ... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 16:57:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33005#M24191</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-12-19T16:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: gotoassist application recognition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33006#M24192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello dieterb,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it may be possible sometimes to see the apps as citrix-jedi and gotomeeting and so on. Sometimes when the software product change a certain behavior for gotoassist in this case, if it is not updated on PAN app signature we may see such issues. And also all of these belong to same parent company there may be overlaps as seen below.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="goto-.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10405_goto-.PNG.png" /&gt;&lt;/P&gt;&lt;P&gt;In such cases, where config looks like gotoassist is allowed but citrix-jedi app is not allowed then while passing traffic if we see some part of gotoassist identified as citrix-jedi and it is getting rejected then we may experience traffic drops..to avoid such issues we may have to open a case to correct the app signature database.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 18:01:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33006#M24192</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-12-19T18:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: gotoassist application recognition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33007#M24193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've put all similar citrix application and even more in the allow policy, but still no go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll probably have to allow services http and https. But I'll try to limit the domains and/or ip's that are actually used (not the entire list of all Citrix SaaS products).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if PA can do anything about it in the application definitions...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Dec 2013 10:41:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gotoassist-application-recognition/m-p/33007#M24193</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-12-20T10:41:56Z</dc:date>
    </item>
  </channel>
</rss>

