<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incomplete  traffic: custom appID and QoS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161672#M52579</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In terms of App-ID, these are connections where not enough data, or data that did not match any known applications's behavior, were transferred and App-ID was unable to identify a known application.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When this type of application is seen inside the organization, there's a good chance this is benign traffic: maybe a homebrew backup or a scripted maintenance task. If these show up on sessions going out to, or coming in from the internet, they should be a reason for concern.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Pro-Tips-Unknown-Applications/ta-p/77052" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Pro-Tips-Unknown-Applications/ta-p/77052&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other words, "Incomplete" is not an application and that's why it is not going to be showed in the "Application" column when you create a security rule or QoS rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My recommendation is that in this case, you create a security policy and QoS policy applying the "Solarwinds" app-id signture to it, then it may take care of this for you. Now if you don't want that traffic to go through the App-ID engine, I recommend that you create a Application Override Policy, so it will bypass the Application inspection. By doing that, you still can apply security profiles but the rule will be treated as stateful only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Willian&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2017 19:43:29 GMT</pubDate>
    <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
    <dc:date>2017-06-16T19:43:29Z</dc:date>
    <item>
      <title>Incomplete  traffic: custom appID and QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161649#M52575</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have traffic generated by Solarwinds NetPath probes that is tagged by the firewall as "incomplete".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I run a packet trace, and after the handshake, there are only TCP-keep-alive packets. &amp;nbsp;I'd like to prioritize this traffic in QoS, currently I'm seeing high latency on NetPath at our busiest sites, and I'm thinking this may be because of QoS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I cannot see "incomplete" as an app in QoS, so I have a couple of questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is incomplete&amp;nbsp;traffic being treated as unknown-tcp/udp?&lt;/P&gt;&lt;P&gt;2. Will I be able to create a custom AppID without an http stream I can base a signature on, to have QoS apply to this traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 18:47:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161649#M52575</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-16T18:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: Incomplete  traffic: custom appID and QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161672#M52579</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In terms of App-ID, these are connections where not enough data, or data that did not match any known applications's behavior, were transferred and App-ID was unable to identify a known application.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When this type of application is seen inside the organization, there's a good chance this is benign traffic: maybe a homebrew backup or a scripted maintenance task. If these show up on sessions going out to, or coming in from the internet, they should be a reason for concern.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Pro-Tips-Unknown-Applications/ta-p/77052" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Pro-Tips-Unknown-Applications/ta-p/77052&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other words, "Incomplete" is not an application and that's why it is not going to be showed in the "Application" column when you create a security rule or QoS rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My recommendation is that in this case, you create a security policy and QoS policy applying the "Solarwinds" app-id signture to it, then it may take care of this for you. Now if you don't want that traffic to go through the App-ID engine, I recommend that you create a Application Override Policy, so it will bypass the Application inspection. By doing that, you still can apply security profiles but the rule will be treated as stateful only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Willian&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 19:43:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161672#M52579</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-16T19:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Incomplete  traffic: custom appID and QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161724#M52590</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In terms of App-ID, these are connections where not enough data, or data that did not match any known applications's behavior, were transferred and App-ID was unable to identify a known application.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When this type of application is seen inside the organization, there's a good chance this is benign traffic: maybe a homebrew backup or a scripted maintenance task. If these show up on sessions going out to, or coming in from the internet, they should be a reason for concern.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Pro-Tips-Unknown-Applications/ta-p/77052" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Pro-Tips-Unknown-Applications/ta-p/77052&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other words, "Incomplete" is not an application and that's why it is not going to be showed in the "Application" column when you create a security rule or QoS rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My recommendation is that in this case, you create a security policy and QoS policy applying the "Solarwinds" app-id signture to it, then it may take care of this for you. Now if you don't want that traffic to go through the App-ID engine, I recommend that you create a Application Override Policy, so it will bypass the Application inspection. By doing that, you still can apply security profiles but the rule will be treated as stateful only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi Willian,&lt;/P&gt;&lt;P&gt;In this case I'm positive that the traffic in question is benign, in fact, I'm trying to prioritize it. &amp;nbsp;Sorry I don't undesrtand your suggestion of "&lt;SPAN&gt;create a security policy and QoS policy applying the "Solarwinds" app-id signture to it. &amp;nbsp;I guess I can't think of how this could possibly work&lt;/SPAN&gt;, since&amp;nbsp;the firewall is not assigning an&amp;nbsp;app tag&amp;nbsp;in the first place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Never used app override, but from a quick peek, it looks as though you need to create a custom appID first, which brings me back to my question 2. &amp;nbsp;Maybe the only way to do this is to forget the app, and use a service based rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 22:04:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161724#M52590</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-16T22:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Incomplete  traffic: custom appID and QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161725#M52591</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If the firewall is not assigning the App -ID is because the application is potentially trying to run over a non-standard port. In this case you have to create your policy allowing the solarwinds application, but leave the service column as "Any", unless you know exactly over which port the service is running on.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Only creating a service based rule will not bypass the app-id engine. You have to create app override policy so that the app-id engine will not interfere with traffic. You assumption is correct, you have to create a custom app-id in order to create an app-override policy, but you still need to know over which port the service is running over.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 22:22:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161725#M52591</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-16T22:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Incomplete  traffic: custom appID and QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161727#M52592</link>
      <description>&lt;P&gt;I was just looking at that document you linked. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &amp;nbsp;I know the port (443), port does not change, and the probes are sent just by a couple of servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, if I create a custom appID (like in the example), with just dest. port tcp/443 but no signature, and then assign that custom app to override app policy (specifying correct source and dest IPs), you think that would work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure I'd define NetPath as an application, it's more like a TCP-based probe? &amp;nbsp;It basically establishes a TCP connection over whatever port you specify, and then keeps the connection alive for a while, rinse and repeat. &amp;nbsp;Which is probably why the firewall has a hard time giving it a name, there is not much to go on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 22:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161727#M52592</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-16T22:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Incomplete  traffic: custom appID and QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161731#M52594</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;&lt;/P&gt;&lt;P&gt;NetPath is not specified as an application in the App-ID library. In this case you have to use the Solarwinds application in the security rule. According to this Solarwinds documentation below,&amp;nbsp;&lt;SPAN class="NPMNetPath"&gt;NetPath&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;is a feature of Solarwinds NPM, and by default displays NPM data and issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.solarwinds.com/documentation/en/flarehelp/npm/content/npm-orion-integration-with-netpath.htm" target="_blank"&gt;http://www.solarwinds.com/documentation/en/flarehelp/npm/content/npm-orion-integration-with-netpath.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would configure the policy according to the screenshot below, based on your explanation and the requirements in the documentation above.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="SolarWinds-Security-Policy.PNG" style="width: 632px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9767iBCA1925B28A656A0/image-dimensions/632x86/is-moderation-mode/true?v=v2" width="632" height="86" role="button" title="SolarWinds-Security-Policy.PNG" alt="SolarWinds-Security-Policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am including the SSL application in case you are running the service over port 443, which seems to be the case. I am also leaving the Service as "ANY" in case the service using non-standard ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 01:11:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161731#M52594</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-17T01:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Incomplete  traffic: custom appID and QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161734#M52595</link>
      <description>&lt;P&gt;Thanks Willian. &amp;nbsp;I'll give this a try on Monday and report back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 02:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/161734#M52595</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-17T02:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Incomplete  traffic: custom appID and QoS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/162020#M52642</link>
      <description>&lt;P&gt;Hi Willian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an existing security rule that already allows NetPath traffic. &amp;nbsp;I created a QoS rule with the apps you listed, and I can see the rule showing up in Network &amp;gt; QoS &amp;gt; Statistics &amp;gt; QoS Rules. &amp;nbsp;So maybe that's it?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 17:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-traffic-custom-appid-and-qos/m-p/162020#M52642</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-19T17:50:12Z</dc:date>
    </item>
  </channel>
</rss>

