<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Applipedia - search by port number? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38057#M27867</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know if it's possible to search for an application by port number instead of name, to see if you can find a match?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some connections using an application that shows a known - and recognised - PORT number when I run a packet capture, vis-a-vis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;12:49:53.009216 IP (tos 0x0, ttl 128, id 47750, offset 0, flags [none], proto: UDP (17), length: 260) www.xxx.yyy.zzz.epnsdp &amp;gt; someone.else.somewhere.net.62395: [udp sum ok] UDP, length 232&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which shows the proocol as epnsdp (UDP 2051, which matches the descriptions I can find for this port by JFGI) but I can't find if there's already a defined application which I might be able to use for this traffic in a policy (rather than the app-override I've got now) before I bother PA with a request for a new application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want to go through all 1200-odd applications looking for this port so I can try applications and see if they match under some other name than what the guys using it know it as.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this isn't as muddled as it sounds to me. Oh well. Maybe someone will have an idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Dec 2010 02:09:43 GMT</pubDate>
    <dc:creator>dagibbs</dc:creator>
    <dc:date>2010-12-14T02:09:43Z</dc:date>
    <item>
      <title>Applipedia - search by port number?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38057#M27867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know if it's possible to search for an application by port number instead of name, to see if you can find a match?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some connections using an application that shows a known - and recognised - PORT number when I run a packet capture, vis-a-vis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;12:49:53.009216 IP (tos 0x0, ttl 128, id 47750, offset 0, flags [none], proto: UDP (17), length: 260) www.xxx.yyy.zzz.epnsdp &amp;gt; someone.else.somewhere.net.62395: [udp sum ok] UDP, length 232&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which shows the proocol as epnsdp (UDP 2051, which matches the descriptions I can find for this port by JFGI) but I can't find if there's already a defined application which I might be able to use for this traffic in a policy (rather than the app-override I've got now) before I bother PA with a request for a new application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want to go through all 1200-odd applications looking for this port so I can try applications and see if they match under some other name than what the guys using it know it as.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this isn't as muddled as it sounds to me. Oh well. Maybe someone will have an idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 02:09:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38057#M27867</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2010-12-14T02:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Applipedia - search by port number?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38058#M27868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can search applications by port in the Applipedia:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://ww2.paloaltonetworks.com/applipedia/"&gt;http://ww2.paloaltonetworks.com/applipedia/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't find anything using port 2051.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if you did find a matching port, it may not be the same application since App-ID's don't use port numbers for the signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you allow the port through via security policy the firewall will still do App-ID so you can check the identified application in the logs.&amp;nbsp; If it comes up as "unknown-udp" then you will need to open a case to have the application added to in a future content release.&amp;nbsp; A PCAP may be requested to get the signature written.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 02:50:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38058#M27868</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-12-14T02:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Applipedia - search by port number?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38059#M27869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;kbrazil wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can search applications by port in the Applipedia:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://ww2.paloaltonetworks.com/applipedia/"&gt;http://ww2.paloaltonetworks.com/applipedia/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't find anything using port 2051.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if you did find a matching port, it may not be the same application since App-ID's don't use port numbers for the signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you allow the port through via security policy the firewall will still do App-ID so you can check the identified application in the logs.&amp;nbsp; If it comes up as "unknown-udp" then you will need to open a case to have the application added to in a future content release.&amp;nbsp; A PCAP may be requested to get the signature written.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I gave up on this one and just put in an any/any rule to allow the traffic out - it's one weird app. I've got a single packet captured, so I might chuck it into an app request and see if one of the fellas with brains at PA can make head or tails or it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 03:16:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38059#M27869</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2010-12-14T03:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Applipedia - search by port number?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38060#M27870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: left;"&gt;Thanks this helped out a lot!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 18:34:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/applipedia-search-by-port-number/m-p/38060#M27870</guid>
      <dc:creator>rob.burgoyne</dc:creator>
      <dc:date>2011-09-22T18:34:45Z</dc:date>
    </item>
  </channel>
</rss>

