<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Teamviewer is not blocking in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232512#M66690</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The firewall is capable of still identifying certain applications through a number of different ways that aren't encrypted when you are using SSL. Under the&amp;nbsp;&lt;EM&gt;majority&lt;/EM&gt; of use cases the firewall is perfectly capable of identifying teamviewer traffic without decrypting the traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI: On a rainy day dig into a technical_support file generated from your firewall and you&amp;nbsp;might just maybe be able to find things you aren't really meant to see &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Sep 2018 19:10:00 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-09-26T19:10:00Z</dc:date>
    <item>
      <title>Teamviewer is not blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232200#M66637</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have PA-820 with fully updated signatures, I have blocked Teamviewer via security policy. PA is recognising the application and traffic log showing that teamviewer connection is blocked but on host machine teamviewer is running and outbound / inbound teamviewer connections are sucessful. I have also tried by applying ssl decryption but still same result. Need help in this regard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shuaib Khalid&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 06:19:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232200#M66637</guid>
      <dc:creator>Shuaib_Khalid</dc:creator>
      <dc:date>2018-09-25T06:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Teamviewer is not blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232258#M66640</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83148"&gt;@Shuaib_Khalid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you have logs proving that the Teamviewer app-id is properly getting blocked when your security rule is applied then this would more then likely be due to traffic getting mis-identified, likely to 'ssl'. To get this to work properly you would need to apply ssl-decryption.&lt;/P&gt;&lt;P&gt;Out of curiosity are you blocking all of the app-ids? You would either include the app-id container of 'teamviewer' and then 'teamviewer-web' or you would need to list out&amp;nbsp; all 4 individually. Generally in my experience the firewall is rather good at identifying teamviewer traffic and blocking it when you are decrypting traffic.&lt;/P&gt;&lt;P&gt;If you aren't decrypting traffic then teamviewer falls back to tcp/443 instead of its default port of tcp/5938 and the firewall will allow the traffic as it can't tell what it is.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could attempt to do this in a controlled situation and reviewing the logs to see what exactly the firewall is identifying the traffic; that may help in understanding why your traffic isn't getting identified properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 13:38:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232258#M66640</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-25T13:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Teamviewer is not blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232451#M66674</link>
      <description>&lt;P&gt;We do not use any form of SSL decryption on our PA, but we are still able to effectively block Teamviewer. Does the firewall perhaps do some kind of hostname/FQDN match in addition to block the traffic? I see in the traffic logs that Teamviewer first tries port tcp/5938, then tcp/443 then tcp/80, but all the sessions are blocked&amp;nbsp;with app-id teamviewer-base.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 13:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232451#M66674</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2018-09-26T13:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: Teamviewer is not blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232512#M66690</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The firewall is capable of still identifying certain applications through a number of different ways that aren't encrypted when you are using SSL. Under the&amp;nbsp;&lt;EM&gt;majority&lt;/EM&gt; of use cases the firewall is perfectly capable of identifying teamviewer traffic without decrypting the traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI: On a rainy day dig into a technical_support file generated from your firewall and you&amp;nbsp;might just maybe be able to find things you aren't really meant to see &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 19:10:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/teamviewer-is-not-blocking/m-p/232512#M66690</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-26T19:10:00Z</dc:date>
    </item>
  </channel>
</rss>

