<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unnown-TCP application &amp;quot;commvault&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114456#M45321</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this situation, if an app signature has been created but is not recognising the app correctly then your best bet is to raise a case with TAC, they are very helpful in assisting you so that the right data is gathered and getting the signature modified accordingly so that it is recognised.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could try and create a custom application for this as well:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Notes/Custom-Application-Signatures/ta-p/58625" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tech-Notes/Custom-Application-Signatures/ta-p/58625&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Tue, 20 Sep 2016 08:29:24 GMT</pubDate>
    <dc:creator>bmorris1</dc:creator>
    <dc:date>2016-09-20T08:29:24Z</dc:date>
    <item>
      <title>Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114324#M45308</link>
      <description>&lt;P&gt;Hi Guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you guys can help with classifying unknown traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read many forums for this topic none of which answer my specific question. I understand that should create a custom app if your application bespoke and it is unlikely that an APP-ID would be created.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am expereincing an issue with an application called "commvault" the firewall already recognises this app, but my rule does not work as the traffic is being identified as "unknown-tcp" I do not understand if the firewall already reconises this app why is this being recognised as unknown. Can you also share with me the correct procedure of getting the traffic classified as "commvault" application?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already have PCAPS from the firewall, but do not know where this should be raised.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many Thanks,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 20:58:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114324#M45308</guid>
      <dc:creator>inzamam.shahid</dc:creator>
      <dc:date>2016-09-19T20:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114332#M45310</link>
      <description>&lt;P&gt;Can you share the traffic log of the "commvault" traffic and the "unkown-tcp" traffic?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 21:10:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114332#M45310</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-09-19T21:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114456#M45321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this situation, if an app signature has been created but is not recognising the app correctly then your best bet is to raise a case with TAC, they are very helpful in assisting you so that the right data is gathered and getting the signature modified accordingly so that it is recognised.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could try and create a custom application for this as well:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Notes/Custom-Application-Signatures/ta-p/58625" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tech-Notes/Custom-Application-Signatures/ta-p/58625&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 08:29:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114456#M45321</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-09-20T08:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114489#M45326</link>
      <description>&lt;P&gt;yes, please share traffic logs and if possible, please show your security policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it is possible the version of commvault you are running differs from the traffic pattern included in the AppID version of commvault.&lt;/P&gt;
&lt;P&gt;(this can be due to a new updte to commvault or a deployment not seen before by our AppId team,...) if that is the case you'd need to open a support ticket to have the behavior of your commvault app verified and appid updated to include it's patern&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 09:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114489#M45326</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-09-20T09:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114548#M45338</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="unknown-tcp_commvault.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5645iF908A3FB7622FF73/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="unknown-tcp_commvault.PNG" alt="unknown-tcp_commvault.PNG" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rules.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5646iAB42F112A0FC4776/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rules.PNG" alt="rules.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see traffic log and the rules that have been created for this.&lt;BR /&gt;&lt;BR /&gt;Please let me know if you guys believe this is correct and if the support route still needs to be followed.&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 11:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114548#M45338</guid>
      <dc:creator>inzamam.shahid</dc:creator>
      <dc:date>2016-09-20T11:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114581#M45344</link>
      <description>&lt;P&gt;you're hitting a deny rule&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you create a security policy that matches the source and destination IP, but leaves the application as any (temorarily), do you still see unknown-tcp ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 12:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114581#M45344</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-09-20T12:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114610#M45346</link>
      <description>&lt;P&gt;This is what I am failing to understand on why it is hitting that deny rule. That deny rule is number 800 in the rule set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The commvault rules are 600 in the rule set. In the screenshot, that I provided "commVault Media Agent to Ping" &amp;amp; "New Backup Networks" are basically any any rules just set to specfic IP's. They let any application over any service go through. I have checked the correct zones and IP's are in the rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I do a a security policy match from the CLI, the rule matches rule called "NEW BACKUP NETWORKS-app" so I do not understand why unknown-tcp is being hit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 13:33:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114610#M45346</guid>
      <dc:creator>inzamam.shahid</dc:creator>
      <dc:date>2016-09-20T13:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114624#M45353</link>
      <description>&lt;P&gt;That's what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;was trying to help figure out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As he stated it's possible there was an update to the APP-ID packge which changed how "commvault" is being idenfitied in your firewall, and while you've properly configured your security policy to use the application it's not matching for that reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So he was asking does it match L3 IP-IP (with applicable zones). &amp;nbsp;Then when introducing the L7 application control is it matching or not.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 14:04:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/114624#M45353</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-09-20T14:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/407766#M92257</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good Evening,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please go through this link:&amp;nbsp;&lt;A href="https://documentation.commvault.com/commvault/v11/article?p=8572.htm" target="_self"&gt;https://documentation.commvault.com/commvault/v11/article?p=8572.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I hope the above link will help you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;
&lt;P&gt;Anita&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 15:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/407766#M92257</guid>
      <dc:creator>Anita2020</dc:creator>
      <dc:date>2021-05-19T15:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unnown-TCP application "commvault"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/585983#M116952</link>
      <description>&lt;P&gt;&lt;SPAN&gt;"Unknown-TCP" traffic from Commvault refers to network traffic generated by Commvault software that is using TCP (Transmission Control Protocol) but is unrecognized or unidentified by the network monitoring system.&lt;BR /&gt;This type of traffic can occur due to various reasons such as custom configurations, non-standard ports, or unexpected communication patterns.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Understanding and scrutinizing this traffic is crucial for network security and performance management, ensuring it doesn't compromise network integrity or impede &lt;A title="Data backup" href="https://parablu.com/" target="_self"&gt;data backup&lt;/A&gt; processes. &lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 09:45:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unnown-tcp-application-quot-commvault-quot/m-p/585983#M116952</guid>
      <dc:creator>parablu</dc:creator>
      <dc:date>2024-05-07T09:45:27Z</dc:date>
    </item>
  </channel>
</rss>

