<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Application match... Sophos-live-protection to 8.8.8.8 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229518#M65983</link>
    <description>&lt;P&gt;Our logs show a numebr of connections from our DC's to port "53" application sophos-live-protection...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's fair enough, I understand the concept of what sophos are tryign to do with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I don't understand is why the destination is 8.8.8.8 and not one of the sophos listening addresses...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't suppose anyone sees this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Wed, 05 Sep 2018 10:34:45 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2018-09-05T10:34:45Z</dc:date>
    <item>
      <title>Application match... Sophos-live-protection to 8.8.8.8</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229518#M65983</link>
      <description>&lt;P&gt;Our logs show a numebr of connections from our DC's to port "53" application sophos-live-protection...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's fair enough, I understand the concept of what sophos are tryign to do with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I don't understand is why the destination is 8.8.8.8 and not one of the sophos listening addresses...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't suppose anyone sees this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 10:34:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229518#M65983</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-09-05T10:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Application match... Sophos-live-protection to 8.8.8.8</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229536#M65986</link>
      <description>&lt;P&gt;I've seen this before with some clients in our network. The clients had Sophos installed, and the software in some way manipulated DNS requests from the client (I haven't used Sophos myself so I cannot be any more specific). This would be DNS requests for external domains which is why your DC's forward them to external DNS servers. Palo Alto sees the DNS traffic, parses the content, notices the Sophos content and changes the appid from dns to sophos-live-protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had a case with TAC about it, and the only solution&amp;nbsp;they suggested was to make an Application Override.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 12:41:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229536#M65986</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2018-09-05T12:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Application match... Sophos-live-protection to 8.8.8.8</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229547#M65995</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I expect that as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;&amp;nbsp;mentioned you have Sophos installed, which would explain why you are seeing this behavior. I don't actually recommend doing the application-override in this situation, however that would be a decision you need to make with the knowledge that application-override stops further application identification from taking place. Since DNS is a heavy target for tunneling all sorts of communication traffic, I personally would avoid this like the plague.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 13:39:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229547#M65995</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-05T13:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Application match... Sophos-live-protection to 8.8.8.8</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229555#M66003</link>
      <description>&lt;P&gt;(yes we do have Sophos, and I have asked them why it's hapening, not much help as yet)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure it's consistent with the explination above..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sophos-live-protection should send information to "SOPHOS" not to "GOOGLE" using port "53" ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the Sophos Client did a DNS lookup for the sophos destination, that would appear as standard DNS lookup via the Domain controller and be a standard DNS lookup on the firewall. Once that IP is&amp;nbsp;resolved the sophos client would send a sophos-live-protection pracket using port 53 to that resolved destination ,not involving the Domain Controller and it would probably discard it anywa as a malformed DNS request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying Packet captures is a bit fruitless as the source/destination/dport are all used by the legitmate DNS traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 14:03:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229555#M66003</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-09-05T14:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: Application match... Sophos-live-protection to 8.8.8.8</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229556#M66004</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's been a while since I supported any Sophos clients and really looked at this, but Sophos used to&amp;nbsp;&lt;EM&gt;always&lt;/EM&gt; send DNS queries with generic information regardless of what you were doing. Any DNS request also included a fair bit of Sophos required information, regardless of where it was destined.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since this information is included within the DNS request, and since Palo Alto built the signature to look for this information, the DNS requests sent via a Sophos protected client will be recorded as sophos-live-protection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 14:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-match-sophos-live-protection-to-8-8-8-8/m-p/229556#M66004</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-05T14:11:50Z</dc:date>
    </item>
  </channel>
</rss>

