<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCoIP traffic getting dropped because it's using SSL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69204#M40200</link>
    <description>&lt;P&gt;You will need to add ssl decryption to allow the firewall inspect the ciphered traffic.&lt;/P&gt;
&lt;P&gt;you can also create a custom SSL application,&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/API-Articles/Custom-Application-for-SSL-based-traffic/ta-p/54774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/API-Articles/Custom-Application-for-SSL-based-traffic/ta-p/54774&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Gerardo.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2015 19:01:00 GMT</pubDate>
    <dc:creator>glastra1</dc:creator>
    <dc:date>2015-12-08T19:01:00Z</dc:date>
    <item>
      <title>PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69195#M40193</link>
      <description>&lt;P&gt;I have VMWare View clients and I'm trying to set up the rule with the vmware-view App-ID, but the traffic gets dropped at&amp;nbsp;PCoIP. The PA logs are showing tcp/4172 as SSL, even though PCoIP has port tcp/4172 defined.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this an issue with the App-ID not identifying secure PCoIP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 18:23:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69195#M40193</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2015-12-08T18:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69197#M40194</link>
      <description>&lt;P&gt;Do you use application-default as service?&lt;/P&gt;
&lt;P&gt;Try to change this temporarily to "any" to see if it works then.&lt;/P&gt;
&lt;P&gt;Also add SSL to list of permitted apps.&lt;/P&gt;
&lt;P&gt;If it starts working then it is probably because SSL has 443 as default port.&lt;/P&gt;
&lt;P&gt;Don't leave service as any for long run but configure manually needed ports.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 18:26:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69197#M40194</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-12-08T18:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69198#M40195</link>
      <description>&lt;P&gt;Yes, I've added SSL to the permitted apps. I had it set to application-default.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When&amp;nbsp;I set service to "Any", it works. But it still shows port 4172 as SSL.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 18:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69198#M40195</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2015-12-08T18:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69199#M40196</link>
      <description>&lt;P&gt;Palo Alto firewall identifies application on any port.&lt;/P&gt;
&lt;P&gt;It looks at traffic pattern and sees that this is actually SSL no matter what port it runs on.&lt;/P&gt;
&lt;P&gt;Add your custom service and configure this manually instead of application-default (that allows ssl on 443 only).&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 18:33:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69199#M40196</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-12-08T18:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69200#M40197</link>
      <description>&lt;P&gt;So what is the point of the "vmware-view" app-id? I thought that was supposed to identify this traffic&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 18:38:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69200#M40197</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2015-12-08T18:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69202#M40198</link>
      <description>&lt;P&gt;Not sure if vmware view will keep on working but try to decrypt this traffic.&lt;/P&gt;
&lt;P&gt;Will it still be identified as ssl?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 18:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69202#M40198</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-12-08T18:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69203#M40199</link>
      <description>&lt;P&gt;No I haven't tried that yet. Thanks for the info&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 18:46:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69203#M40199</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2015-12-08T18:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69204#M40200</link>
      <description>&lt;P&gt;You will need to add ssl decryption to allow the firewall inspect the ciphered traffic.&lt;/P&gt;
&lt;P&gt;you can also create a custom SSL application,&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/API-Articles/Custom-Application-for-SSL-based-traffic/ta-p/54774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/API-Articles/Custom-Application-for-SSL-based-traffic/ta-p/54774&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Gerardo.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 19:01:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69204#M40200</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2015-12-08T19:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69208#M40201</link>
      <description>&lt;P&gt;application-default means that if the traffic is coming on the default port it will be allowed. For example for SSL the defautl port number is 443. Now if the SSL traffic comes on port 8080 and the service is application-default PA will not allow that traffic because SSL is not coming on default port.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 19:51:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69208#M40201</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-08T19:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69209#M40202</link>
      <description>&lt;P&gt;I think I understand that, but why does the PA identify certain SSL traffic by it's application name, while others are just "SSL"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, Facebook is over port 443, but it doesn't say "SSL" in the logs, it says "facebook-base". Same thing for other pre-decryption applications, like Google.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So why can't the PA identifiy "vmware-view" instead of just "SSL"?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 20:01:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69209#M40202</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2015-12-08T20:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69210#M40203</link>
      <description>&lt;P&gt;Facebook is easy to identify by the Common Name field of the certificate (generally *.facebook.com). Many other popular SSL applications work the same way. From that, the firewall can determine that while it is SSL, it's actually&amp;nbsp;Facebook.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your VMWare View app is likely going to a server with a private IP address, or is a doman name that is unknown to the application database. That's why it's only SSL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you decrypt the traffic, the firewall can see beyond the key handshake, and can identify the traffic by its actual requests and responses. Until you decrypt it, the firewall only has access to the handshake itself.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 20:16:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69210#M40203</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-12-08T20:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69279#M40247</link>
      <description>&lt;P&gt;We run VMWare View (now Horizon) in our environment. &amp;nbsp;Our experience is that the built in vmware-view application did not work for us.&amp;nbsp; It seems to expect that all the services will run on one server, which is a little bit unrealistic.&amp;nbsp; I think Palo Alto should have split them down into their individual applications within View rather than trying to bundle them.&amp;nbsp; For instance, you may not want to allow RDP for instance, or USB redirection, but by default they are included.&amp;nbsp; When you start looking to block these it can get tricky and downright just not work because of “rules validation”.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our case we have separate view hosting and security servers.&amp;nbsp; For us to get it to work correctly we had to configure custom applications, application overrides, and a few rules for view.&amp;nbsp; Note that View was the only application that we had to do this for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Custom Apps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1557iEF4925374F2B582B/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="view custom apps.jpg" title="view custom apps.jpg" width="814" height="67" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Application Override&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1558iE5709246CC6DBFB5/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="application override.jpg" title="application override.jpg" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rules&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1559i3FFC3CED135B3F1F/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="view rules.jpg" title="view rules.jpg" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remember that PCoIP streams on UDP/4172.&amp;nbsp; The TCP/4172 side of PCoIP is used for control, which simply looks to be SSL traffic just on a custom port, which is probably why Palo Alto firewalls sees it as SSL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not a fan of having&amp;nbsp;turn off layer 7 application inspection for these particular servers and ports, but this seemed to be the only option. &amp;nbsp;If anyone else has done this in a more simplified manner, I would love to hear about it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 21:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/69279#M40247</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2015-12-09T21:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/74739#M41774</link>
      <description>&lt;P&gt;Nice, thanks for taking the time to write&amp;nbsp;an informative answer. I didn't know&amp;nbsp;the other features such as USB were over a different port, I thought it was all tunneled over SSL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I look at my&amp;nbsp;traffic, I'm only seeing ports 80, 443, and 8443. It seems everything is tunneled over SSL. We are using a VMAP server though, which all clients must connect to first. Maybe thats the difference?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 17:36:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/74739#M41774</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2016-03-16T17:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: PCoIP traffic getting dropped because it's using SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/74946#M41839</link>
      <description>&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica','sans-serif'; color: #333333;"&gt;Are you sure that your clients are configured for PCoIP? &amp;nbsp;Make sure you check the Horizon Client and make sure PCoIP is checked in the options.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; orphans: auto; text-align: start; widows: 1; -webkit-text-stroke-width: 0px; word-spacing: 0px;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica','sans-serif'; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; orphans: auto; text-align: start; widows: 1; -webkit-text-stroke-width: 0px; word-spacing: 0px;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica','sans-serif'; color: #333333;"&gt;If you are using a security server (such as for public facing clients), SSL will be used for the connection protocol and to encapsulate RDP&lt;SPAN class="apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;(TCP) traffic. &amp;nbsp;PCoIP, from what I've&amp;nbsp;experienced, is a completely different stream UDP stream that will be need to be allowed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; orphans: auto; text-align: start; widows: 1; -webkit-text-stroke-width: 0px; word-spacing: 0px;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica','sans-serif'; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; orphans: auto; text-align: start; widows: 1; -webkit-text-stroke-width: 0px; word-spacing: 0px;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica','sans-serif'; color: #333333;"&gt;That being said, I didn't set up our View environment, so i can't speak to if its set up in accordance to best practices or not&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 20:26:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pcoip-traffic-getting-dropped-because-it-s-using-ssl/m-p/74946#M41839</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2016-03-18T20:26:13Z</dc:date>
    </item>
  </channel>
</rss>

