<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application = insufficient-data? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43386#M31828</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Insufficient data" means that the packet is too small to be identified.&amp;nbsp; It may be hitting the first rule where the service is set to "any" , which happens to be your ftp allow policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Apr 2010 23:36:12 GMT</pubDate>
    <dc:creator>nrice</dc:creator>
    <dc:date>2010-04-26T23:36:12Z</dc:date>
    <item>
      <title>Application = insufficient-data?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43385#M31827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have some outgoing UDP traffic that shows up in the traffic log with "insufficient-data" in the application field. The problem is that this traffic is being allowed through the firewall because it's being matched to a rule that allows FTP traffic through. What does the firewall mean by "insufficient data", and why does it think it's FTP traffic, when FTP uses TCP, not UDP? Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 15:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43385#M31827</guid>
      <dc:creator>ahopkins</dc:creator>
      <dc:date>2010-04-26T15:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Application = insufficient-data?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43386#M31828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Insufficient data" means that the packet is too small to be identified.&amp;nbsp; It may be hitting the first rule where the service is set to "any" , which happens to be your ftp allow policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 23:36:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43386#M31828</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-04-26T23:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Application = insufficient-data?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43387#M31829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 May 2010 13:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43387#M31829</guid>
      <dc:creator>ahopkins</dc:creator>
      <dc:date>2010-05-04T13:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Application = insufficient-data?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43388#M31830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are seeing this also.&amp;nbsp; It onlyh appears on an FTP rule.&lt;/P&gt;&lt;P&gt;I think this is misbehaviour on the part of PA, since we are allowing FTP and only FTP, yet if the Application is not determinable PA's logic just passes it anyway?&amp;nbsp; This behaviour is inappropriate and dangerous.&amp;nbsp; Why not just drop it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 20:40:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43388#M31830</guid>
      <dc:creator>frank_henry</dc:creator>
      <dc:date>2012-01-04T20:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Application = insufficient-data?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43389#M31831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to have that clarified too, please.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 19:36:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43389#M31831</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2012-11-08T19:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Application = insufficient-data?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43390#M31832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the firewall gets a packets related to any application. The firewall will take 7-14 packets (depending on the applications ) roughly to identify what kind of application. So during these first initial packets the firewall does not what the application is and it is trying to identify the application, as a result these initial packets will show up as insufficient data. But after these packets initial packets the firewall will be able to determine the application and will match the according security rules. Normally you will see these insufficient data packets hitting the first rule on the firewall ( if the rule is blocking/allowing traffic based on applications). Here is the reason for this &lt;/P&gt;&lt;P&gt;For example you have a rule at the top of your rule list as below.&lt;/P&gt;&lt;P&gt;Rule named as "DENY_FB" to deny all the traffic which is of application "facebook".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now assume now your are sending gmail traffic to the firewall. Since the firewall does not what the application is, it does not what to do with this. This traffic could be facebook or anything else. so it will match the top rule until it identifies the application and during this time it logs this as insufficient data. Once it determines the application it will no longer match the top rule it will match the correct rule. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 20:33:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43390#M31832</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-11-08T20:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: Application = insufficient-data?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43391#M31833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understand that but it still doesn't explain what it does with these insufficient-data packets before it is able to identify them. Regarding to my logs, all of these packets are allowed. So whatever rule it hits, those packets are forwarded? Why doesn't it block them until identified? Huge security risk.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 20:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43391#M31833</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2012-11-08T20:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Application = insufficient-data?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43392#M31834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most likely because various protocols ("applications") are similar to other protocols and by that more packets must be let through before the NGFW can make a positive identification (with low false positive rate).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a start you need at least 2 packets in one direction and 1 in the other just for the tcp handshake to complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On top of that identifying a general web-browsing should be fairly easy because the request should look like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;METHOD URI HTTP/VERSION&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and some other headers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats one of the reasons for why you should never use "service:any" but rather "service:application-default" or even better specify which PROTO/PORT you wish to allow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 21:02:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-insufficient-data/m-p/43392#M31834</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-08T21:02:24Z</dc:date>
    </item>
  </channel>
</rss>

