<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Handling Unknown TCP iSCSI traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78268#M42878</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the application can be identified by matching a string of characters in the session a custom app with a custom signature would do the trick&lt;/P&gt;
&lt;P&gt;If the traffic has no identifyable markers, an app override would allow you to set the application manually. the app override rule can have address objects both as source and destination. these address objects can be a single IP, a subnet or an IP range&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please check out these articles:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635" target="_blank"&gt;Getting Started: Custom applications and app override&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Videos/How-to-Configure-a-Custom-App-ID/ta-p/55815" target="_self"&gt; How to Configure a Custom App-ID&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Pro-Tips-Unknown-Applications/ta-p/77052" target="_blank"&gt; Pro-Tips: Unknown Applications &lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2016 07:10:49 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-05-18T07:10:49Z</dc:date>
    <item>
      <title>Handling Unknown TCP iSCSI traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78256#M42875</link>
      <description>&lt;P&gt;I have&amp;nbsp; a Dell Equalogic SAN that is replication to an offsite location. The traffic is sent over via a VPN tunnel (Certificate based). This traffic is being reported as unknown tcp. I can verify that the traffic in question is in fact the SAN traffic as the source and destination matches.&amp;nbsp;I also read that the PA normally flags certificate based VPN as unknown. I need to get this traffic reported as a correct application as unknown is hard to manage and add to the fact that PA recommends blocking unknown TCP traffic. I also need to create a QoS rule so that this traffic is provided a higher priority.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe what I am needing to create is an Application override based on some of the articles here. Assuming this is correct and will provide me with the requirements; I need to have several IP addresses in this policy. Can I create an application group with a subnet; for example, all SAN traffic is outbound on 10.0.52.x (10.0.52.1-10.0.52-9) or do I have to create the group with each IP address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is not the ideal solution or will not provide the results I am seeking, can you provide me with the KB or solution that would?&amp;nbsp; Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 21:58:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78256#M42875</guid>
      <dc:creator>jharlow</dc:creator>
      <dc:date>2016-05-17T21:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Handling Unknown TCP iSCSI traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78268#M42878</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the application can be identified by matching a string of characters in the session a custom app with a custom signature would do the trick&lt;/P&gt;
&lt;P&gt;If the traffic has no identifyable markers, an app override would allow you to set the application manually. the app override rule can have address objects both as source and destination. these address objects can be a single IP, a subnet or an IP range&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please check out these articles:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Custom-applications-and-app-override/ta-p/71635" target="_blank"&gt;Getting Started: Custom applications and app override&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Videos/How-to-Configure-a-Custom-App-ID/ta-p/55815" target="_self"&gt; How to Configure a Custom App-ID&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Pro-Tips-Unknown-Applications/ta-p/77052" target="_blank"&gt; Pro-Tips: Unknown Applications &lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 07:10:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78268#M42878</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-18T07:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Handling Unknown TCP iSCSI traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78322#M42905</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created a new application and configured the settings to idenfity any traffic that is using port 3260 (tcp/3260); however, I am still seeing "unknown-tcp" in the monitor logs. I do not believe I can use a signature or at least in the examples I found as the data is encrypted (IPsec), so there is no Get statement in the TCP segment. Only traffic that is on 3260 is iSCSI and needs to be identified.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4072iCACC9EF9DB156173/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4073i4EB8D458FBC1BACD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture1.JPG" alt="Capture1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 16:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78322#M42905</guid>
      <dc:creator>jharlow</dc:creator>
      <dc:date>2016-05-18T16:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Handling Unknown TCP iSCSI traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78327#M42907</link>
      <description>&lt;P&gt;Disregard. Deteremine that I had to also create a application override. Once that was in place, traffic is now identify correctly. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 17:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/handling-unknown-tcp-iscsi-traffic/m-p/78327#M42907</guid>
      <dc:creator>jharlow</dc:creator>
      <dc:date>2016-05-18T17:34:20Z</dc:date>
    </item>
  </channel>
</rss>

