<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Skype Stun Not Allowed due to incorrect UDP Port in APP-ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/128723#M46720</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of my customers is having an issue where by Skype is not being allowed through despite the Stun and RTP applications being allowed through:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="skype-allow-rule.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6500i15D7EB4C94F42F23/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="skype-allow-rule.png" alt="skype-allow-rule.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Previously we'd used the 'skype' and 'skype-probe' but this was not matching with the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking through the traffic logs the traffic is being denied because Stun is running on a high level port and not the default TCP/UDP 3478:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="skype-traffic-deny.png" style="width: 729px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6501i43737875F4287758/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="skype-traffic-deny.png" alt="skype-traffic-deny.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to ARIN this entire range is assigned to Microsoft so making the assumption this is Skype traffic:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Net Range&lt;/TD&gt;&lt;TD&gt;104.40.0.0 - 104.47.255.255&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CIDR&lt;/TD&gt;&lt;TD&gt;104.40.0.0/13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name&lt;/TD&gt;&lt;TD&gt;MSFT&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Handle&lt;/TD&gt;&lt;TD&gt;NET-104-40-0-0-1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This customer does not have URL filtering filtering installed so we are unable to permit/deny based on any details included in that. &amp;nbsp;The infrastructure also does not permit FQDN for using dynamic IP address lookups, hence the any in the destination IP rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the present we have allowed this traffic by setting the service to 'any' not 'application-default'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The device is a PA-5050 running 7.0.11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else hit this issue and know of a fix?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One other thing I'd thought about doing is to clone the built-in 'stun' application (e.g. 'skype-stun') so that I can specify alternative port or set it to dynamic but it doesn't seem possible to do that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gu&lt;/P&gt;</description>
    <pubDate>Thu, 24 Nov 2016 14:40:59 GMT</pubDate>
    <dc:creator>Gukaaran</dc:creator>
    <dc:date>2016-11-24T14:40:59Z</dc:date>
    <item>
      <title>Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/128723#M46720</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of my customers is having an issue where by Skype is not being allowed through despite the Stun and RTP applications being allowed through:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="skype-allow-rule.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6500i15D7EB4C94F42F23/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="skype-allow-rule.png" alt="skype-allow-rule.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Previously we'd used the 'skype' and 'skype-probe' but this was not matching with the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking through the traffic logs the traffic is being denied because Stun is running on a high level port and not the default TCP/UDP 3478:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="skype-traffic-deny.png" style="width: 729px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6501i43737875F4287758/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="skype-traffic-deny.png" alt="skype-traffic-deny.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to ARIN this entire range is assigned to Microsoft so making the assumption this is Skype traffic:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Net Range&lt;/TD&gt;&lt;TD&gt;104.40.0.0 - 104.47.255.255&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CIDR&lt;/TD&gt;&lt;TD&gt;104.40.0.0/13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name&lt;/TD&gt;&lt;TD&gt;MSFT&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Handle&lt;/TD&gt;&lt;TD&gt;NET-104-40-0-0-1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This customer does not have URL filtering filtering installed so we are unable to permit/deny based on any details included in that. &amp;nbsp;The infrastructure also does not permit FQDN for using dynamic IP address lookups, hence the any in the destination IP rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the present we have allowed this traffic by setting the service to 'any' not 'application-default'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The device is a PA-5050 running 7.0.11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else hit this issue and know of a fix?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One other thing I'd thought about doing is to clone the built-in 'stun' application (e.g. 'skype-stun') so that I can specify alternative port or set it to dynamic but it doesn't seem possible to do that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gu&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 14:40:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/128723#M46720</guid>
      <dc:creator>Gukaaran</dc:creator>
      <dc:date>2016-11-24T14:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/129024#M46740</link>
      <description>&lt;P&gt;You could simply apply an applicaiton override policy to that traffic that looks like the screenshot I took. Simply put it will label anything that goes to that specific port and to the specified destination addresses as 'stun' traffic.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6522i764B2BB1EB0D355D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing to point out is that looking at the rule that you shared it doesn't look like you are using an 'application-default' service entry; therefore you should be seeing the traffic being allowed as long as it is hitting that rule.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 17:32:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/129024#M46740</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-11-25T17:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131114#M46908</link>
      <description>&lt;P&gt;Thanks for the reply BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because the port defined for Stun in the PA's application defintion is different to the port being used by actual traffic, I believe this is why it's not matching.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had a read of application override and I don't believe this is what my customer will want as it disables any further APP-ID inspection:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;As soon as the Application Override policy takes effect, all further App-ID inspection of the traffic is stopped and the session is identified with the custom application."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ref:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Because it's not possible to lock the rule down by destination IP we'd effectively be allowing any traffic out of the network just as long as goes on the correct port number, this is definately not ideal.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What I'd really like to be able to do is tell the Palo Alto that this port should be used by Stun and have it pass through the same level of filtering as if it was using the default port defined in the Stun application.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 12:26:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131114#M46908</guid>
      <dc:creator>Gukaaran</dc:creator>
      <dc:date>2016-12-05T12:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131116#M46909</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you try to create&amp;nbsp;a custom add for stun without policy override:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=CwXdWJpw0UY" target="_blank"&gt;https://www.youtube.com/watch?v=CwXdWJpw0UY&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 12:40:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131116#M46909</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-05T12:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131139#M46912</link>
      <description>&lt;P&gt;Not tried a custom app as yet as I don't know what signatures to apply in order to match the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All I need is for Stun to be matched on the different port but using the same signatures. &amp;nbsp;Would creating a custom app and setting 'Stun' as the parent but with a different port number achieve the same thing and inherit the original signatures? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm thinking from&amp;nbsp;the below paragraph that it won't as it would need to trigger the parent app first which is not on the correct port:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;For example, if you build a custom application that triggers on a host header &lt;/SPAN&gt;&lt;A href="http://www.mywebsite.com" target="_blank"&gt;www.mywebsite.com&lt;/A&gt;&lt;SPAN&gt;, the packets are first identified as &lt;/SPAN&gt;web-browsing&lt;SPAN&gt; and then are matched as your custom application (whose parent application is web-browsing). Because the parent application is web-browsing, the custom application is inspected at Layer-7 and scanned for content and vulnerabilities."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ref:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/app-id/manage-custom-or-unknown-applications" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/app-id/manage-custom-or-unknown-applications&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 13:22:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131139#M46912</guid>
      <dc:creator>Gukaaran</dc:creator>
      <dc:date>2016-12-05T13:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131149#M46914</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you create a separate policy for stun app and identify in services as upd/tcp&amp;nbsp;3478 and 3480? Would that&amp;nbsp;work ? This is without app override&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="stun.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6715i4390290FBBF4A3EA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="stun.PNG" alt="stun.PNG" /&gt;&lt;/span&gt;﻿&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="for stun.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6716i047DDC79225ECCB0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="for stun.PNG" alt="for stun.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 14:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131149#M46914</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-05T14:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131152#M46915</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did try that at the beginning but it didn't match the application as it was not on the expected port. That's why the service port is currently set to 'Any'. Based on the below paragraph, what you suggest should have worked but we found it didn't:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Use &lt;/SPAN&gt;application-default&lt;SPAN&gt; for the &lt;/SPAN&gt;Service&lt;SPAN&gt;. The firewall compares the port used with the list of default ports for that application. If the port used is not a default port for the application, the firewall drops the session and logs the message &lt;/SPAN&gt;appid policy lookup deny&lt;SPAN&gt;. If you have a application that is accessed on many ports and you would like to limit the ports on which the application is used, specify it in &lt;/SPAN&gt;Service&lt;SPAN&gt; /&lt;/SPAN&gt; Service Group&lt;SPAN&gt; objects in policies."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ref: &lt;A href="https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/app-id/best-practices-for-using-app-id-in-policy" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/app-id/best-practices-for-using-app-id-in-policy&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It's been a couple of weeks so going to need to review this again.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 14:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/131152#M46915</guid>
      <dc:creator>Gukaaran</dc:creator>
      <dc:date>2016-12-05T14:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/466164#M102659</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there an update on this topic ?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 12:04:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/466164#M102659</guid>
      <dc:creator>EmreOzeel</dc:creator>
      <dc:date>2022-02-16T12:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Skype Stun Not Allowed due to incorrect UDP Port in APP-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/517604#M107409</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;SSL Decryption configuration must be done to prevent stun traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 12:34:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-stun-not-allowed-due-to-incorrect-udp-port-in-app-id/m-p/517604#M107409</guid>
      <dc:creator>EmreOzeel</dc:creator>
      <dc:date>2022-10-12T12:34:05Z</dc:date>
    </item>
  </channel>
</rss>

