<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allowing some protocols from any user/port? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-some-protocols-from-any-user-port/m-p/36985#M27148</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am curious what others are doing for some protocols:&amp;nbsp; Examples:&amp;nbsp; DNS, ocsp, STUN, meraki, apple push notification, etc.&amp;nbsp; It seems to me that these sorts of things could be let go for pretty much all users, anytime and be excluded from the captive portal.&amp;nbsp; Correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a couple fo reasons for this question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; I am having issues with Facetime which I believe is occurring because device is trying to talk to the apple servers before the user has yet to authenticate to the captive portal.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; STUN is trying to get out on some ports which are "nonstandard".&amp;nbsp; It seems that I could let STUN go on any port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Jan 2013 17:20:40 GMT</pubDate>
    <dc:creator>BobW</dc:creator>
    <dc:date>2013-01-22T17:20:40Z</dc:date>
    <item>
      <title>Allowing some protocols from any user/port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-some-protocols-from-any-user-port/m-p/36985#M27148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am curious what others are doing for some protocols:&amp;nbsp; Examples:&amp;nbsp; DNS, ocsp, STUN, meraki, apple push notification, etc.&amp;nbsp; It seems to me that these sorts of things could be let go for pretty much all users, anytime and be excluded from the captive portal.&amp;nbsp; Correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a couple fo reasons for this question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; I am having issues with Facetime which I believe is occurring because device is trying to talk to the apple servers before the user has yet to authenticate to the captive portal.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; STUN is trying to get out on some ports which are "nonstandard".&amp;nbsp; It seems that I could let STUN go on any port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 17:20:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-some-protocols-from-any-user-port/m-p/36985#M27148</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2013-01-22T17:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing some protocols from any user/port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-some-protocols-from-any-user-port/m-p/36986#M27149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob, &lt;/P&gt;&lt;P&gt;If you are having issue with facetime then you can allow that as an applicaiton instead of using the ports. You can configure the Palo Alto firewall to either allow the traffic based on ports or applications. If it is allowed based on application then it checks the traffic and even if it is on non-standard ports it allows it.&lt;/P&gt;&lt;P&gt;If you allow it as an application then firewall will check the traffic and make sure which ever session belongs to facetime is allowed .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the application details on face time from the firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;LABEL class="x-form-item-label" for="ext-comp-1360" id="ext-gen1071" style="text-align: left; padding-top: 3px; padding-right: 3px; padding-bottom: 3px;"&gt;&lt;STRONG&gt;Name:&amp;nbsp; &lt;/STRONG&gt;&lt;/LABEL&gt;&lt;/P&gt;&lt;DIV class=" x-form-display-field" id="ext-comp-1360" style="padding-top: 4px;"&gt;facetime&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P class="x-form-item " id="ext-gen1072" style="margin-bottom: 4px; font-family: tahoma, helvetica, arial, sans-serif; font-size: 11px; color: #222222; text-align: -webkit-auto; background-color: #ebedee;"&gt;&lt;LABEL class="x-form-item-label" for="ext-comp-1361" id="ext-gen1073" style="text-align: left; padding-top: 3px; padding-right: 3px; padding-bottom: 3px;"&gt;&lt;STRONG&gt;Description:&amp;nbsp; &lt;/STRONG&gt;&lt;/LABEL&gt;&lt;/P&gt;&lt;DIV class="x-form-element" id="x-form-el-ext-comp-1361" style="padding-left: 185px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;&lt;DIV class=" x-form-display-field" id="ext-comp-1361" style="padding-top: 4px;"&gt;FaceTime is a video calling software feature for iPhone 4's phone application, developed by Apple. It is based on numerous open standards: H.264 and AAC - video and audio codecs; SIP - IETF signaling protocol for VoIP; STUN, TURN, and ICE - IETF technologies for traversing firewalls and NAT; RTP and SRTP - IETF standards for delivering real-time and encrypted media streams for VoIP.&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P class="x-form-item " id="ext-gen1074" style="margin-bottom: 4px; font-family: tahoma, helvetica, arial, sans-serif; font-size: 11px; color: #222222; text-align: -webkit-auto; background-color: #ebedee;"&gt;&lt;LABEL class="x-form-item-label" for="ext-comp-1362" id="ext-gen1075" style="text-align: left; padding-top: 3px; padding-right: 3px; padding-bottom: 3px;"&gt;&lt;STRONG&gt;Additional Information:&amp;nbsp; &lt;/STRONG&gt;&lt;/LABEL&gt;&lt;/P&gt;&lt;DIV class="x-form-element" id="x-form-el-ext-comp-1362" style="padding-left: 185px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;&lt;DIV class=" x-form-display-field" id="ext-comp-1362" style="padding-top: 4px;"&gt;&lt;A href="http://www.apple.com/iphone/features/facetime.html" style="color: #5396b8;" target="_blank"&gt;FaceTime&lt;/A&gt;&amp;nbsp; &lt;A href="http://en.wikipedia.org/wiki/FaceTime" style="color: #5396b8;" target="_blank"&gt;Wikipedia&lt;/A&gt;&amp;nbsp; &lt;A href="http://www.google.com/search?q=facetime" style="color: #5396b8;" target="_blank"&gt;Google&lt;/A&gt;&amp;nbsp; &lt;A href="http://search.yahoo.com/search?q=facetime" style="color: #5396b8;" target="_blank"&gt;Yahoo!&lt;/A&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P class="x-form-item " id="ext-gen1076" style="margin-bottom: 4px; font-family: tahoma, helvetica, arial, sans-serif; font-size: 11px; color: #222222; text-align: -webkit-auto; background-color: #ebedee;"&gt;&lt;LABEL class="x-form-item-label" for="ext-comp-1363" id="ext-gen1077" style="text-align: left; padding-top: 3px; padding-right: 3px; padding-bottom: 3px;"&gt;&lt;STRONG&gt;Standard Ports:&amp;nbsp; &lt;/STRONG&gt;&lt;/LABEL&gt;&lt;/P&gt;&lt;DIV class="x-form-element" id="x-form-el-ext-comp-1363" style="padding-left: 185px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;&lt;DIV class=" x-form-display-field" id="ext-comp-1363" style="padding-top: 4px;"&gt;tcp/80,443,3478-3497,4080,5223, udp/3478,16384-16387,16393-16402&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P class="x-form-item " id="ext-gen1078" style="margin-bottom: 4px; font-family: tahoma, helvetica, arial, sans-serif; font-size: 11px; color: #222222; text-align: -webkit-auto; background-color: #ebedee;"&gt;&lt;LABEL class="x-form-item-label" for="ext-comp-1364" id="ext-gen1079" style="text-align: left; padding-top: 3px; padding-right: 3px; padding-bottom: 3px;"&gt;&lt;STRONG&gt;Depends on Applications:&amp;nbsp; &lt;/STRONG&gt;&lt;/LABEL&gt;&lt;/P&gt;&lt;DIV class="x-form-element" id="x-form-el-ext-comp-1364" style="padding-left: 185px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;&lt;DIV class=" x-form-display-field" id="ext-comp-1364" style="padding-top: 4px;"&gt;ichat-av, sip, ssl, stun, web-browsing&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another thing to notice here is that facetime has dependent application as well. So if you block those applications before the rule of face time then you might not be able to get the facetime going.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 23:46:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-some-protocols-from-any-user-port/m-p/36986#M27149</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-01-22T23:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing some protocols from any user/port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-some-protocols-from-any-user-port/m-p/36987#M27150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The facetime problem is a bit tricky as I believe it has something to do with traffic going out pre captive portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&amp;nbsp; I have enabled the dependencies.&amp;nbsp; I have a rule at the bottom of my ruleset which blocks all protocols that get that far.&amp;nbsp; For STUN in particular I am seeing a lot of traffic to ports other than the default of 3478 which are being blocked by my bottom most rule.&amp;nbsp; So this goes back to part of the question.&amp;nbsp; Would it be beneficial (or detrimental) to have a rule that allows STUN to go out on any port or just stick with the default of 3478?&amp;nbsp; Right now I have a rule that lets STUN out for "application default" only, thus udp 3478.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2013 00:59:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-some-protocols-from-any-user-port/m-p/36987#M27150</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2013-01-23T00:59:22Z</dc:date>
    </item>
  </channel>
</rss>

