<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Erroneous application port in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154582#M50909</link>
    <description>&lt;P&gt;I am getting a deny statement for port 8531 for application ssl. 8531 is for ms-update and my policy allows that but the default policy is denying it because it is tying it to ssl for some strange reason. I don't know how to get around that.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2017 19:56:46 GMT</pubDate>
    <dc:creator>tglear</dc:creator>
    <dc:date>2017-04-28T19:56:46Z</dc:date>
    <item>
      <title>Erroneous application port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154582#M50909</link>
      <description>&lt;P&gt;I am getting a deny statement for port 8531 for application ssl. 8531 is for ms-update and my policy allows that but the default policy is denying it because it is tying it to ssl for some strange reason. I don't know how to get around that.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 19:56:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154582#M50909</guid>
      <dc:creator>tglear</dc:creator>
      <dc:date>2017-04-28T19:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Erroneous application port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154589#M50910</link>
      <description>&lt;P&gt;What app-version are you running? I haven't seen this issue come across at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Temp workarounds:&lt;/P&gt;&lt;P&gt;1) Create an application override policy that specifies Microsoft's IP range and override port 8531 to ms-update instead of ssl.&lt;/P&gt;&lt;P&gt;2) Create a custom security&amp;nbsp;policy for the traffic and you don't need to create an override policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really do verify that this is actually ms-update traffic though and pass along your app-version so that we know what version you are on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 20:08:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154589#M50910</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-04-28T20:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Erroneous application port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154593#M50913</link>
      <description>&lt;P&gt;What PAN-OS are you on? Try to change the "services" tab to &amp;nbsp;any&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 20:18:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154593#M50913</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-28T20:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Erroneous application port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154804#M50963</link>
      <description>&lt;P&gt;if you're seeing ssl blocked on that port, this means there's an ssl session being initiated on that port, possibly something trying to bypass a traditional port based firewall (ssl will be detected if the packets have the appropriate behavior for ssl, client hello etc. )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you want to figure out what exactly is hitting your firewall, you can set up a packetcapture for that port and see what comes out. most likely something is sending a client hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you may not want to 'get around that' until you can determine what exactly is going on, this may be C&amp;amp;C from an infected host&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 06:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/erroneous-application-port/m-p/154804#M50963</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-05-02T06:48:02Z</dc:date>
    </item>
  </channel>
</rss>

