<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA apps in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-apps/m-p/169545#M53849</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are expecting problem with PA identifying apps.&lt;/P&gt;&lt;P&gt;We have sessions in port 13000 being identified as play-station network. These sessions are not related to Pstation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the another hand, we also have sessions in port 80 being identified as unknown-tcp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why PA is idenfitying like this?? how can we solve this app problem??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2017 09:38:52 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2017-08-02T09:38:52Z</dc:date>
    <item>
      <title>PA apps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-apps/m-p/169545#M53849</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are expecting problem with PA identifying apps.&lt;/P&gt;&lt;P&gt;We have sessions in port 13000 being identified as play-station network. These sessions are not related to Pstation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the another hand, we also have sessions in port 80 being identified as unknown-tcp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why PA is idenfitying like this?? how can we solve this app problem??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 09:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-apps/m-p/169545#M53849</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-08-02T09:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA apps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-apps/m-p/169560#M53853</link>
      <description>&lt;P&gt;You can get PCAP &amp;nbsp;from these sessions as well as try to reinstall newer app-database or even reinstall already existing one. &amp;nbsp;But be honest, not sure what is going on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 09:48:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-apps/m-p/169560#M53853</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-02T09:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: PA apps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-apps/m-p/169623#M53862</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9102"&gt;@soporteseguridad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;unknown-tcp sessions are fairly common and are exactly that, usually it's because the session didn't actually process enough traffic to identify the app-id or the app-id simply doesn't exist.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The playstation-network identification is odd simply because the application doesn't actually use that port range by default. My guess is that you are not decrypting the traffic and therefore the firewall is trying it's best but will have false-positives or miss app-ids at times simply based off of how the feature functions and the amount of information it can see with the information it has access to without SSL decryption enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;stated the best course of action would be taking PCAPs and attempting to figure out what the traffic actually is. If the traffic is known you can build out a custom application signature to identify the traffic correctly and if you can identify it further you can pass the infromation along so that Palo Alto can attempt to narrow the application signature if at all possible so it's not flagging traffic incorrectly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:17:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-apps/m-p/169623#M53862</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-02T15:17:41Z</dc:date>
    </item>
  </channel>
</rss>

