<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA cannot distinguish between Dropbox and Cloudfront in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169772#M53901</link>
    <description>&lt;P&gt;Please open a TAC case. They will have to inspect this and get it rectified if its a decoder issue.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2017 08:51:34 GMT</pubDate>
    <dc:creator>abjain</dc:creator>
    <dc:date>2017-08-03T08:51:34Z</dc:date>
    <item>
      <title>PA cannot distinguish between Dropbox and Cloudfront</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169689#M53889</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA does not seem to be able to distinguish between Dropbox and Cloudfront. In the Traffic logs, all sessions are identified as dropbox-base. Outputs from show session id:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DROPBOX:&lt;/P&gt;&lt;P&gt;start time : Thu Aug 3 09:58:15 2017&lt;BR /&gt;timeout : 120 sec&lt;BR /&gt;total byte count(c2s) : 4843&lt;BR /&gt;total byte count(s2c) : 6128&lt;BR /&gt;layer7 packet count(c2s) : 11&lt;BR /&gt;layer7 packet count(s2c) : 12&lt;BR /&gt;vsys : vsys1&lt;BR /&gt;application : dropbox-base&lt;BR /&gt;rule : Staff&lt;BR /&gt;session to be logged at end : True&lt;BR /&gt;session in session ager : False&lt;BR /&gt;session updated by HA peer : False&lt;BR /&gt;address/port translation : source&lt;BR /&gt;nat-rule : STAFF_NAT(vsys1)&lt;BR /&gt;layer7 processing : completed&lt;BR /&gt;URL filtering enabled : False&lt;BR /&gt;session via syn-cookies : False&lt;BR /&gt;session terminated on host : False&lt;BR /&gt;session traverses tunnel : False&lt;BR /&gt;captive portal session : False&lt;BR /&gt;ingress interface : vlan.100&lt;BR /&gt;egress interface : ethernet1/1&lt;BR /&gt;session QoS rule : N/A (class 4)&lt;BR /&gt;tracker stage l7proc : ctd decoder bypass&lt;BR /&gt;end-reason : aged-out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CLOUDFRONT:&lt;/P&gt;&lt;P&gt;start time : Thu Aug 3 10:03:34 2017&lt;BR /&gt;timeout : 30 sec&lt;BR /&gt;total byte count(c2s) : 3485141&lt;BR /&gt;total byte count(s2c) : 96056293&lt;BR /&gt;layer7 packet count(c2s) : 46500&lt;BR /&gt;layer7 packet count(s2c) : 63461&lt;BR /&gt;vsys : vsys1&lt;BR /&gt;application : dropbox-base&lt;BR /&gt;rule : Access Rule&lt;BR /&gt;session to be logged at end : True&lt;BR /&gt;session in session ager : False&lt;BR /&gt;session updated by HA peer : False&lt;BR /&gt;address/port translation : source&lt;BR /&gt;nat-rule : ACCESS_NAT(vsys1)&lt;BR /&gt;layer7 processing : completed&lt;BR /&gt;URL filtering enabled : False&lt;BR /&gt;session via syn-cookies : False&lt;BR /&gt;session terminated on host : False&lt;BR /&gt;session traverses tunnel : False&lt;BR /&gt;captive portal session : False&lt;BR /&gt;ingress interface : vlan.100&lt;BR /&gt;egress interface : ethernet1/1&lt;BR /&gt;session QoS rule : N/A (class 4)&lt;BR /&gt;tracker stage firewall : TCP RST - client&lt;BR /&gt;tracker stage l7proc : ctd decoder bypass&lt;BR /&gt;end-reason : tcp-rst-from-client&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-OS: 8.0.3 using latest content version.&lt;/P&gt;&lt;P&gt;Any idea how to fix this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 00:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169689#M53889</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-08-03T00:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: PA cannot distinguish between Dropbox and Cloudfront</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169772#M53901</link>
      <description>&lt;P&gt;Please open a TAC case. They will have to inspect this and get it rectified if its a decoder issue.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 08:51:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169772#M53901</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2017-08-03T08:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: PA cannot distinguish between Dropbox and Cloudfront</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169789#M53905</link>
      <description>&lt;P&gt;It doesn't appear you are using SSL decryption? You may need to enable decryption to be able to look inside the flow and properly identify the apps&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 09:46:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169789#M53905</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-08-03T09:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA cannot distinguish between Dropbox and Cloudfront</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169862#M53927</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Without decryption the firewalls app-id is kind of in a 'best guess' situation. It'll identify the application to the best of it's ability but the ability to do application identification is limited when you only give the device limited availability into the device. The only real fix would be to decrypt the traffic; if you open a TAC case they'll probably look at it and tell you the same thing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wouldn't really rely on the app-id being correct if you aren't decrypting the traffic, they can only inspect the headers and such within the traffic flow to try and identify the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 15:19:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-cannot-distinguish-between-dropbox-and-cloudfront/m-p/169862#M53927</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-03T15:19:51Z</dc:date>
    </item>
  </channel>
</rss>

