<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About undecided application. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43402#M31840</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mikand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you wrote "insufficient-data' means that is not enough data packets for identifying the application. I think insufficient-data, not to be identified app-id, was undecided application on session browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However in my case, UNDECIDED traffic had got so many packets and data exceed over about 1.3GB on session browser. Its traffic could be insufficient-data? I suspect that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When captured PCAPs, the traffic was recognized NFS protocol on wireshark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Roh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Jul 2012 07:37:18 GMT</pubDate>
    <dc:creator>ttongfly</dc:creator>
    <dc:date>2012-07-04T07:37:18Z</dc:date>
    <item>
      <title>About undecided application.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43400#M31838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some question about APP-ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For session browser, PAN recognized application was UNDECIDED and traffic was passed and state was ACTIVE. so traffic was not dropped but why PAN could not recognized application properly and recognizing UNDECIDED that means PAN could not identified APP-ID for its traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Why PAN could not recognized properly app-id and session browser showed app-id was UNDECIDED?&lt;/P&gt;&lt;P&gt;2. What is UNDECIDED mean exactly on session browser?&lt;/P&gt;&lt;P&gt;3. UNDECIDED application traffic has got a so many packets (of course this traffic over the 7 packets that could do identifying app-id)&amp;nbsp; and bytes. so I think PAN should recognize this traffic as a proper app-id.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know why did PAN recognize UNDECIDE as a app-id on session browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Roh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2012 05:38:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43400#M31838</guid>
      <dc:creator>ttongfly</dc:creator>
      <dc:date>2012-07-04T05:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: About undecided application.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43401#M31839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Undecided?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the admin guide an app can be "unknown" where the reason can be either "incomplete" or "insufficient-data".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where "incomplete" means that a handshake took place but no data packets were sent prior to the timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And "insufficient-data" means that a handshake took place followed by one or more data packets. However not enough data packets were exchanged to identify the application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To fix this you can either create a custom appid or contact PA to make it into the common appid database:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can request app enhancement from the Apps and Threats Research Center.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.paloaltonetworks.com/researchcenter/tools/"&gt;http://www.paloaltonetworks.com/researchcenter/tools/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From there you can click on Submit an app and provide details there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case to answer why the PA didnt identify your traffic you would need to provide either the forum, or better, the appid request team with a pcap.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2012 06:15:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43401#M31839</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-04T06:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: About undecided application.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43402#M31840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mikand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you wrote "insufficient-data' means that is not enough data packets for identifying the application. I think insufficient-data, not to be identified app-id, was undecided application on session browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However in my case, UNDECIDED traffic had got so many packets and data exceed over about 1.3GB on session browser. Its traffic could be insufficient-data? I suspect that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When captured PCAPs, the traffic was recognized NFS protocol on wireshark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Roh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2012 07:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43402#M31840</guid>
      <dc:creator>ttongfly</dc:creator>
      <dc:date>2012-07-04T07:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: About undecided application.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43403#M31841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried putting NFS protocol/App on your block list/filter?. Then try capturing sessions if "undecided" still shows up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 00:02:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/43403#M31841</guid>
      <dc:creator>Kali</dc:creator>
      <dc:date>2012-07-06T00:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: About undecided application.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/594747#M118377</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Security Rule Behavior with Applications Allowed with Service 'Any'&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVmCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVmCAK&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Why do Sessions Show Application "Undecided" When in ACTIVE State but have an App When Moved to DISCARD State?&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLK0CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLK0CAO&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;These are the ones that helped me to understand it!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 13:31:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-undecided-application/m-p/594747#M118377</guid>
      <dc:creator>paulocamargoagility</dc:creator>
      <dc:date>2024-08-13T13:31:25Z</dc:date>
    </item>
  </channel>
</rss>

