<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Server 2012 ms-update in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7927#M5847</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using WSUS to manage our Windows updates. It's hosted on Windows Server 2012 and runs smoothly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently added a Windows Server 2012 in DMZ and pointed it to our WSUS server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;server --- DMZ --- PA2020 --- LAN --- WSUS server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PA2020 does not recognize specific WSUS traffic to the WSUS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is: most detecting/reporting passes fine as application ms-sms.&lt;/P&gt;&lt;P&gt;The actual downloading of updates is not recognized as ms-update, but as web-browsing. That traffic is on the non-default http port 8530 (this is in fact the default port voor WSUS). Our other servers in DMZ (Windows Server 2008 R2) update fine and their traffic to the WSUS server is identified as expected (ms-update).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are on app definition version 391-1924.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone else seeing similar behaviour ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Sep 2013 12:42:30 GMT</pubDate>
    <dc:creator>dieter_b</dc:creator>
    <dc:date>2013-09-09T12:42:30Z</dc:date>
    <item>
      <title>Windows Server 2012 ms-update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7927#M5847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using WSUS to manage our Windows updates. It's hosted on Windows Server 2012 and runs smoothly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently added a Windows Server 2012 in DMZ and pointed it to our WSUS server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;server --- DMZ --- PA2020 --- LAN --- WSUS server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PA2020 does not recognize specific WSUS traffic to the WSUS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is: most detecting/reporting passes fine as application ms-sms.&lt;/P&gt;&lt;P&gt;The actual downloading of updates is not recognized as ms-update, but as web-browsing. That traffic is on the non-default http port 8530 (this is in fact the default port voor WSUS). Our other servers in DMZ (Windows Server 2008 R2) update fine and their traffic to the WSUS server is identified as expected (ms-update).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are on app definition version 391-1924.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone else seeing similar behaviour ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 12:42:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7927#M5847</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-09-09T12:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Server 2012 ms-update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7928#M5848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please report this mis-identification to Support:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5336"&gt;How to Validate and Report Application Misidentification&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 12:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7928#M5848</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-09-09T12:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Server 2012 ms-update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7929#M5849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's a lot of work for an issue thay may or may not exist...&lt;/P&gt;&lt;P&gt;If others report the same findings, I will properly report it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, in your howto it's not clear where that report should go: here in the thread or sending it to support (mail ??)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 13:54:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7929#M5849</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-09-09T13:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Server 2012 ms-update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7930#M5850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The document enlists all the steps to be performed before opening case with support.&lt;/P&gt;&lt;P&gt;In most of the case, PCAPs from &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Windows Server 2012 and &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Windows Server 2008 R2&lt;/SPAN&gt;&lt;/SPAN&gt; should help in validating the application misidentification.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Traffic logs and &lt;STRONG&gt;show session id &amp;lt;id&amp;gt;&lt;/STRONG&gt; o/p&amp;nbsp; from working and nonworking scenario would help in validating the mis-id.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 20:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7930#M5850</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-09-09T20:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Server 2012 ms-update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7931#M5851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have found the same issue.&amp;nbsp; Some of our Admins spun up 2012 WSUS clients in a DMZ and the traffic is not identified.&amp;nbsp; The default port is 8530 as dieterb reported.&amp;nbsp; I will just use an app-override to cope.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 17:13:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7931#M5851</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2014-01-02T17:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Server 2012 ms-update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7932#M5852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could always report it without creating a case if you want to just supply basic info to the application team:&lt;/P&gt;&lt;P&gt;&lt;A href="http://researchcenter.paloaltonetworks.com/submit-an-application/"&gt;http://researchcenter.paloaltonetworks.com/submit-an-application/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That link allows you to submit an app along with your company and email so the content team can get in touch if they need more info. If you have a packet capture, even better. If not, the content team may still be able to redefine that traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 17:22:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-server-2012-ms-update/m-p/7932#M5852</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2014-01-02T17:22:17Z</dc:date>
    </item>
  </channel>
</rss>

