<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Junk traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142377#M48533</link>
    <description>&lt;P&gt;Hi !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's a tricky one!&lt;/P&gt;
&lt;P&gt;the only real way to filter out good from junk is to 'know' the network&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this will most likely require a little legwork where you talk to whomever is responsible for a set of servers to see if they can tell you which connections are needed and which arent, which in most cases will result in the sysadmin replying "ALL PORTS NEED TO BE OPEN" or something along those lines &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can go about creating some custom reports that highlight the overall app category, that should split up most 'business' traffic from 'not so business' and then you can tune from there&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-02-10_16-46-57.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="2017-02-10_16-46-57.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-02-10_16-49-11.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="2017-02-10_16-49-11.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Feb 2017 15:50:32 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-02-10T15:50:32Z</dc:date>
    <item>
      <title>Junk traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142360#M48530</link>
      <description>&lt;P&gt;Is there a good way to verify good traffic from junk traffic.?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 14:49:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142360#M48530</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-02-10T14:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Junk traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142377#M48533</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's a tricky one!&lt;/P&gt;
&lt;P&gt;the only real way to filter out good from junk is to 'know' the network&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this will most likely require a little legwork where you talk to whomever is responsible for a set of servers to see if they can tell you which connections are needed and which arent, which in most cases will result in the sysadmin replying "ALL PORTS NEED TO BE OPEN" or something along those lines &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can go about creating some custom reports that highlight the overall app category, that should split up most 'business' traffic from 'not so business' and then you can tune from there&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-02-10_16-46-57.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="2017-02-10_16-46-57.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-02-10_16-49-11.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="2017-02-10_16-49-11.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 15:50:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142377#M48533</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-02-10T15:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Junk traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142412#M48538</link>
      <description>&lt;P&gt;Good idea reaper I have been trying to use the ACC too. I am trying to tighten up our DMZ &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 16:57:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142412#M48538</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-02-10T16:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Junk traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142437#M48542</link>
      <description>&lt;P&gt;Sadly DMZs take a long time to actually secure properly if they are already running production services. Mgmt doesn't want you to bring anything down, but at the same time I've seen DMZ that was configured to allow anything between their internal zone and had outside RDP open to the servers. Took me a very long time to explain that they had destroyed any reason to have a DMZ in the first place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 18:21:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142437#M48542</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-10T18:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Junk traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142475#M48546</link>
      <description>&lt;P&gt;I hear ya Bpry&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 20:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/junk-traffic/m-p/142475#M48546</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-02-10T20:51:49Z</dc:date>
    </item>
  </channel>
</rss>

