<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking bittorrent traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41328#M30378</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for answering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically my rule is just: 'from any to any', deny application bittorrent.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I can't see what I could possibly have done wrong &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;mario;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Jul 2010 06:32:43 GMT</pubDate>
    <dc:creator>MarioG</dc:creator>
    <dc:date>2010-07-14T06:32:43Z</dc:date>
    <item>
      <title>Blocking bittorrent traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41326#M30376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just found the time to start learning about our new firewall. As a test I have tried creating a policy for blocking bittorrent traffic, but it seems to have only limited effect. Transmission still happily downloads the torrent although I can see from the logs in the firewall that at least some of the traffic is being denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I doing something wrong or is the application id simply not capable of correctly identifying all bittorrent traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;mario;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 07:55:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41326#M30376</guid>
      <dc:creator>MarioG</dc:creator>
      <dc:date>2010-07-13T07:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking bittorrent traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41327#M30377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does your security policy look like?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 18:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41327#M30377</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2010-07-13T18:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking bittorrent traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41328#M30378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for answering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically my rule is just: 'from any to any', deny application bittorrent.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I can't see what I could possibly have done wrong &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;mario;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jul 2010 06:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41328#M30378</guid>
      <dc:creator>MarioG</dc:creator>
      <dc:date>2010-07-14T06:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking bittorrent traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41329#M30379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should have gotten a dependency error when committing. I believe bittorrent also needs web-browsing and ssl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I bet some of the traffic is being classified as different apps in the logs. I would build an application filter using:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="linkDisabled" id="GridView2_ctl02_new_category"&gt;general-internet &amp;gt; &lt;/A&gt;&lt;A class="linkEnabled" id="GridView3_ctl02_sub_category"&gt;file-sharing &amp;gt; peer-to-peer &amp;gt; 5&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should cover all of the various bittorrent apps like ares, kazaa, and even generic-p2p apps. Plus, if Palo Alto ever adds another bittorrent app in their app/content releases, the app will automatically be added to your policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jul 2010 13:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41329#M30379</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2010-07-14T13:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking bittorrent traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41330#M30380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried your suggestion on building the application filter, but unfortunately the result is much the same. It still can't identify all the bittorrent traffic. I think the traffic that is missed is classified as 'unknown-tcp' and 'incomplete'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still don't get any dependancy errors when committing the filters. Should I?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2010 07:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41330#M30380</guid>
      <dc:creator>MarioG</dc:creator>
      <dc:date>2010-07-15T07:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking bittorrent traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41331#M30381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now we are getting somewhere. If you are seeing insufficient-data in the log, that means the firewall did not collect enough packets to determine what the application was. For unknown-tcp, you might want to take a packet capture and submit that to Palo Alto Support. Maybe they need to adjust the decoder for bittorrent traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may or may not get a dependancy error. I haven't created a bittorrent policy since PAN OS 3.0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2010 13:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41331#M30381</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2010-07-15T13:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking bittorrent traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41332#M30382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another factor that could be clouding the issue is that if you have started a download prior to the device or blocking policy being inline, the client will have the ability to use that existing info to connect out to those peers. Particularly with encryption enabled on the client, this will make it very difficult to block. You should have success in blocking as long as we are in place with a blocking rule at the time the initial download occurs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Jul 2010 17:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-bittorrent-traffic/m-p/41332#M30382</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-07-23T17:37:25Z</dc:date>
    </item>
  </channel>
</rss>

