<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom signature for unknown tcp in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203807#M60017</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;&lt;BR /&gt;Thank you both for the fast reply this morning i 've solved the problem by picking the right hexa digits&lt;/P&gt;</description>
    <pubDate>Tue, 06 Mar 2018 11:49:51 GMT</pubDate>
    <dc:creator>oguzhan-sanatci</dc:creator>
    <dc:date>2018-03-06T11:49:51Z</dc:date>
    <item>
      <title>Custom signature for unknown tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203546#M59962</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="20180305_161025.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14114i7450929C5816D74A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="20180305_161025.jpg" alt="20180305_161025.jpg" /&gt;&lt;/span&gt;this is a capture from a tcp traffic.&lt;/P&gt;&lt;P&gt;i want to make a custom app id because in my log it say my application is an unknown-TCP application&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can i get the signature from the digits (image) ?&lt;/P&gt;&lt;P&gt;can someone thell me or give me tips how i should make a custom app id from a packet capture&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 15:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203546#M59962</guid>
      <dc:creator>oguzhan-sanatci</dc:creator>
      <dc:date>2018-03-05T15:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Custom signature for unknown tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203554#M59963</link>
      <description>&lt;P&gt;Coulds you share PCAPs of this application, preferrably from a few different sessions?&amp;nbsp; That would make it much easier to create a custom signature.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another option is to create an "empty" AppID (essentially an AppID without a Layer-7 signature).&amp;nbsp; Then you can create an App-Override policy that maps traffic to your custom application server (using both IP Address &amp;amp; TCP Port #) to your newly-created AppID.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 15:23:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203554#M59963</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-03-05T15:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Custom signature for unknown tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203563#M59965</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84249"&gt;@oguzhan-sanatci&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;&amp;nbsp;pointed out you'll need to provide PCAPs of the traffic to help build the signature or you can create a custom application. WIthin the application you would simply give it any Properties that you actually want it to have, set the default ports if desired, and then leave the actual 'Signature' section empty.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can then build an application override policy that lets you specify a wide range of information. If you know that an internal source reaching out to a specific destination server over tcp 41794-41795 is going to be your custom application you can build a policy for that and it will simply map that traffic to the custom application ID that you created.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 15:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203563#M59965</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-05T15:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Custom signature for unknown tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203807#M60017</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;&lt;BR /&gt;Thank you both for the fast reply this morning i 've solved the problem by picking the right hexa digits&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 11:49:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-signature-for-unknown-tcp/m-p/203807#M60017</guid>
      <dc:creator>oguzhan-sanatci</dc:creator>
      <dc:date>2018-03-06T11:49:51Z</dc:date>
    </item>
  </channel>
</rss>

