<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic About ftp passive mode App-ID insufficient-data in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48531#M35729</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We find that if ftp runs passive mode and go through paloalto fw, in the fw monitor -&amp;gt; logs -&amp;gt; traffic, we'll see the application should be identified as insufficient-data.&lt;/P&gt;&lt;P&gt;I also find that there are just few bytes for every logs in the Bytes column.&lt;/P&gt;&lt;P&gt;Anyone knows how to explain those results&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Mar 2013 04:41:44 GMT</pubDate>
    <dc:creator>paloalto.netfos</dc:creator>
    <dc:date>2013-03-26T04:41:44Z</dc:date>
    <item>
      <title>About ftp passive mode App-ID insufficient-data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48531#M35729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We find that if ftp runs passive mode and go through paloalto fw, in the fw monitor -&amp;gt; logs -&amp;gt; traffic, we'll see the application should be identified as insufficient-data.&lt;/P&gt;&lt;P&gt;I also find that there are just few bytes for every logs in the Bytes column.&lt;/P&gt;&lt;P&gt;Anyone knows how to explain those results&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 04:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48531#M35729</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2013-03-26T04:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: About ftp passive mode App-ID insufficient-data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48532#M35730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Insufficient data means that there was not enough data to identify the application. So for example, if the 3-way TCP handshake completed and there was one data packet after the handshake but that one data packet was not enough to match any of our signatures, you would see insufficient data in the application field of the traffic log..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Ref:&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1549"&gt;Incomplete, Insufficient data and Not-applicable in the application field&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 04:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48532#M35730</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-03-26T04:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: About ftp passive mode App-ID insufficient-data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48533#M35731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for feedbacks quickly. So if ftp runs passive mode and pass through paloalto fw, the fw could not identify it correctly as application "ftp", right? or not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Joy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 06:10:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48533#M35731</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2013-03-26T06:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: About ftp passive mode App-ID insufficient-data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48534#M35732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes ,you would see &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;insufficient-data, if the firewall does not see enough data packets to identify this traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Do you see the traffic matching the expected security rule?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;P.S: Application FTP would cover both Active+Passive variants.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: 1.5em;"&gt;-Ameya&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 07:16:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48534#M35732</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-03-26T07:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: About ftp passive mode App-ID insufficient-data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48535#M35733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Ameya.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"few bytes for every log" also indicates that there's not enough data. Basically, even just to login to ftp server, the traffic size usually becomes a few hundred bytes. The first thing to check is to see whether ftp is really working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Yasu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 09:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48535#M35733</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2013-03-26T09:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: About ftp passive mode App-ID insufficient-data</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48536#M35734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After upgrade content version 364-1728, the pa fw can correctly identified applicatin of ftp passive mode as "ftp" with high random ports.&lt;/P&gt;&lt;P&gt;My security policies setting as below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trust-zone, any source-addresses, to&amp;nbsp; Untrust-zone, any destination-addresses, application eq ftp,service application-default, action eq allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Mar 2013 03:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-ftp-passive-mode-app-id-insufficient-data/m-p/48536#M35734</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2013-03-29T03:25:02Z</dc:date>
    </item>
  </channel>
</rss>

