<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: insufficient-data/incomplete application in logs but still permitted in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4286#M3168</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you are saying that I can specify applications as well as port numbers in a single rule?? I had an issue, admittedly on a differnet os version, that it would not see the service ports or the applications when using them in the same rule - Cant remember which one. I ended up creating 2 differnet rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Jan 2011 08:48:11 GMT</pubDate>
    <dc:creator>hallk</dc:creator>
    <dc:date>2011-01-28T08:48:11Z</dc:date>
    <item>
      <title>insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4278#M3160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am currently only allowing ssl and web-browsing applications to a specific server. If I do a "telnet x.x.x.x 3389" it connects even though the rule should not allow this. I would think that the application filter is unable to block this due to the application coming up as insufficient-data or incomplete.&lt;/P&gt;&lt;P&gt;How do I block this??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 13:47:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4278#M3160</guid>
      <dc:creator>hallk</dc:creator>
      <dc:date>2011-01-27T13:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4279#M3161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably once the telnet is sucessful no further commands can be initiated as the application telnet will be picked up - it is not always immediate, since you need a little info to identify the application.&amp;nbsp; It would be worth checking this doc out:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1628"&gt;https://live.paloaltonetworks.com/docs/DOC-1628&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 14:00:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4279#M3161</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-27T14:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4280#M3162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply, however we were able to run a couple of commands and get some info. The logs showed the app as either incomplete or insufficient-data during the running of these commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 14:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4280#M3162</guid>
      <dc:creator>hallk</dc:creator>
      <dc:date>2011-01-27T14:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4281#M3163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hallk,&lt;/P&gt;&lt;P&gt;are you using "any" in the Service field for web-browsing and ssl applications?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, it can be beneficial to specify specific or default ports for the applications being allowed. If the service is defined as “any” , all sessions must be allowed to start so the system can see if the correct application is running on them. If the service is anything but “any” , then many unwanted connections can be dropped immediately.If the traffic and resulting application does not match any rule, the session will be dropped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 14:29:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4281#M3163</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-01-27T14:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4282#M3164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then I would probably need to see your complete rulebase to find the answer - can you see which rule the traffic is hitting?&amp;nbsp; Is it the one you expected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 14:33:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4282#M3164</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-27T14:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4283#M3165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also a concern is that you are able to run port scan and the report will tell you what ports the box is listening on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 14:59:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4283#M3165</guid>
      <dc:creator>hallk</dc:creator>
      <dc:date>2011-01-27T14:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4284#M3166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This depends on your configuration.&amp;nbsp; Maybe you need to be in contact with your local SE to spend some time with you on these tests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 15:22:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4284#M3166</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-27T15:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4285#M3167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is hitting a rule allowing web-browsing and ssl aplications.&lt;/P&gt;&lt;P&gt;TCP 3389 is definitely not allowed on any rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jan 2011 08:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4285#M3167</guid>
      <dc:creator>hallk</dc:creator>
      <dc:date>2011-01-28T08:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4286#M3168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you are saying that I can specify applications as well as port numbers in a single rule?? I had an issue, admittedly on a differnet os version, that it would not see the service ports or the applications when using them in the same rule - Cant remember which one. I ended up creating 2 differnet rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jan 2011 08:48:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4286#M3168</guid>
      <dc:creator>hallk</dc:creator>
      <dc:date>2011-01-28T08:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4287#M3169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure where you saw the problem - but you can indeed use the application and service column for "extra" security in the same rule.&amp;nbsp; This will mean the application must ONLY run over the ports you have defined in the service column, which maybe custom or the application-default setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jan 2011 10:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4287#M3169</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-28T10:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4288#M3170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys. Will do this and get the audit team to test again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jan 2011 13:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4288#M3170</guid>
      <dc:creator>hallk</dc:creator>
      <dc:date>2011-01-28T13:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4289#M3171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the help. Tested and works perfectly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jan 2011 14:13:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4289#M3171</guid>
      <dc:creator>hallk</dc:creator>
      <dc:date>2011-01-28T14:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: insufficient-data/incomplete application in logs but still permitted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4290#M3172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good news &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;You may want to look into zone protection, if your trying to protect against reconaissance too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Jan 2011 16:04:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/insufficient-data-incomplete-application-in-logs-but-still/m-p/4290#M3172</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-29T16:04:13Z</dc:date>
    </item>
  </channel>
</rss>

