<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ALG (Application Layer Gateway) and Oracle in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182891#M56284</link>
    <description>&lt;P&gt;I wonder if it is typo in GUI that it mentiones SIP ALG in all cases?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sip-alg.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12022i3B82F03A812FB137/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sip-alg.PNG" alt="sip-alg.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2017 22:45:39 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2017-10-19T22:45:39Z</dc:date>
    <item>
      <title>ALG (Application Layer Gateway) and Oracle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182770#M56255</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've an application who has to query an Oracle database to get information from it. There is a PaloAlto firewall between my application and the DB.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually reach the database, but I can't collect the information that I need. Making a quick tcpdump of incoming packets on the server in which my application is running, I noticed on wireshark that, on the response&amp;nbsp;packet of the DB, there is this error: Malformed Packet: TNS.&lt;/P&gt;&lt;P&gt;There is no "deny" on the firewall, I was wondering if it can be related to the ALG&amp;nbsp;functionality. Making some research online I found threads like these, in which is clearly said that the solution is to disable the ALG:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://packetpushers.net/sqlnet-a-k-a-oracle-tns-and-firewalls/" target="_blank"&gt;http://packetpushers.net/sqlnet-a-k-a-oracle-tns-and-firewalls/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://forums.juniper.net/t5/SRX-Services-Gateway/Oracle-TNS-packet-drop-issue/td-p/159316" target="_blank"&gt;https://forums.juniper.net/t5/SRX-Services-Gateway/Oracle-TNS-packet-drop-issue/td-p/159316&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The documentation of PaloAlto states:&amp;nbsp;&lt;BR /&gt;&lt;U&gt;Palo Alto Networks firewall provides NAT ALG support for the following protocols: FTP, H.225, H.248, MGCP, MySQL, Oracle/SQLNet/TNS, RPC, RSH, RTSP, SCCP, SIP, and UNIStim.&lt;BR /&gt;&lt;BR /&gt;&lt;/U&gt;But it is not clear which is the&amp;nbsp;&lt;STRONG&gt;default behavior &lt;/STRONG&gt;of the firewall with these services. It actually performs NAT ALG on all of the services listed, even if you do not specify to use it?&amp;nbsp;&lt;BR /&gt;Furthermore, I saw also that you can disable ALG module just on SIP application. And what if ALG is performed even on the services listed above and you want to disable it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there someone who is able to help me on this matter?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 14:47:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182770#M56255</guid>
      <dc:creator>saul_reps</dc:creator>
      <dc:date>2017-10-19T14:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: ALG (Application Layer Gateway) and Oracle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182780#M56258</link>
      <description>&lt;P&gt;Depending on the application's behavior the ALG&amp;nbsp;accomodates returning packets requiring a pinholed port or 'special' NAT processing, like for example FTP where a new session is set up from the server to the client to provide a data channel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your implementation requires a different methodology than the protocol standard, the ALG could mess things up&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the first place you could try disabling ALG and secondly you could try an app override to a custom app which will disable all content inspection of the traffic in case non-standard (or a new incarnation/update/version that we&amp;nbsp;have not incorporated yet) implementation is being used&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the case of the latter, please reach out to support so we can update our App-ID database&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not quite sure what your question is regarding SIP. Each protocol has it's own decoder and ALG, so disabling one does not interfere with another&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 15:08:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182780#M56258</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-10-19T15:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: ALG (Application Layer Gateway) and Oracle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182787#M56263</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&lt;BR /&gt;In the first place you could try disabling ALG&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The problem is, is it possible to disable ALG just for a single policy?&amp;nbsp; As far as I understand reading the guide (I don't have the access to the PA firewall), it's possible to disable ALG just in case of SIP applications (that's why I mentioned SIP in my previous question).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 17:31:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182787#M56263</guid>
      <dc:creator>saul_reps</dc:creator>
      <dc:date>2017-10-19T17:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: ALG (Application Layer Gateway) and Oracle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182812#M56269</link>
      <description>You disable ALG  at the application level, all the applications you listed can be "opened" individually (click the app in Objects &amp;gt; Applications and check it's settings) and ALG can be disabled per application&lt;BR /&gt;&lt;BR /&gt;Sip is just a common example but all the other apps can be accessed and altered in exactly the same way</description>
      <pubDate>Thu, 19 Oct 2017 18:44:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182812#M56269</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-10-19T18:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: ALG (Application Layer Gateway) and Oracle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182889#M56283</link>
      <description>&lt;P&gt;Looks like ALG can be disabled only in specific applications.&lt;/P&gt;&lt;P&gt;In other cases you can use Application Override.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;# set shared alg-override application
  sccp      application sccp
  sip       application sip
  teredo    application teredo
  unistim   application unistim
  &amp;lt;name&amp;gt;    &amp;lt;name&amp;gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 19 Oct 2017 22:41:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182889#M56283</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-19T22:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: ALG (Application Layer Gateway) and Oracle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182891#M56284</link>
      <description>&lt;P&gt;I wonder if it is typo in GUI that it mentiones SIP ALG in all cases?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sip-alg.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12022i3B82F03A812FB137/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sip-alg.PNG" alt="sip-alg.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 22:45:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-application-layer-gateway-and-oracle/m-p/182891#M56284</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-19T22:45:39Z</dc:date>
    </item>
  </channel>
</rss>

