<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: site-to-site vpn from Sophos in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51127#M37621</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could write a specific rule just for the Sophos site ip address as a port based rule before the application rule. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Apr 2015 09:56:26 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2015-04-02T09:56:26Z</dc:date>
    <item>
      <title>site-to-site vpn from Sophos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51126#M37620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IKE coming from a Sophos device is incorrectly identified as application ciscovpn instead of application ike.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this because Sophos uses cisco-ish protocol ? All I see in the logs is udp 500...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm happy allowing application ike, our other site-to-site vpn's work fine with it.&lt;/P&gt;&lt;P&gt;I'm not happy however with allowing ciscovpn, since that would open a bunch of other ports as well (source applipedia: tcp/500,2512,4500,10000, udp/500,4500,10000,62514-62524)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone noticed similar behaviour ? Can I do something about it ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Apr 2015 15:03:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51126#M37620</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-04-01T15:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: site-to-site vpn from Sophos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51127#M37621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could write a specific rule just for the Sophos site ip address as a port based rule before the application rule. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 09:56:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51127#M37621</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-04-02T09:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: site-to-site vpn from Sophos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51128#M37622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what we did. But still, I would have expected it to work using only application ike...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 08:56:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51128#M37622</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-04-14T08:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: site-to-site vpn from Sophos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51129#M37623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This happens sometimes.&amp;nbsp; Applications are classified based on the actual behavior and content of the packets.&amp;nbsp; So the connection here was similar enough to the Cisco to make a match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could open a support case and provide the pcaps on the misclassification.&amp;nbsp; Then the application signature might be able to be updated in a future release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 09:54:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-sophos/m-p/51129#M37623</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-04-14T09:54:22Z</dc:date>
    </item>
  </channel>
</rss>

