<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic App-ID Issues with Dropbox traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-issues-with-dropbox-traffic/m-p/246014#M70086</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We've got QoS setup on a PA-220 that classes any traffic marked with the dropbox App-ID. This class is then restricted to 2mbps. However we find that not all traffic generated by the Dropbox Sync client is marked as dropbox. Sometimes it's just ssl, sometimes its unknown-udp. Essentially we just want to restrict any Dropbox traffic to 2mbps through the Internet.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How do we achieve this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are using Dropbox as an installed application (not from web browser).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSL Decryption is not enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The concerned policy has 'dropbox' application enabled with application-default.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jan 2019 01:54:15 GMT</pubDate>
    <dc:creator>FarzanaMustafa</dc:creator>
    <dc:date>2019-01-15T01:54:15Z</dc:date>
    <item>
      <title>App-ID Issues with Dropbox traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-issues-with-dropbox-traffic/m-p/246014#M70086</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We've got QoS setup on a PA-220 that classes any traffic marked with the dropbox App-ID. This class is then restricted to 2mbps. However we find that not all traffic generated by the Dropbox Sync client is marked as dropbox. Sometimes it's just ssl, sometimes its unknown-udp. Essentially we just want to restrict any Dropbox traffic to 2mbps through the Internet.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How do we achieve this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are using Dropbox as an installed application (not from web browser).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSL Decryption is not enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The concerned policy has 'dropbox' application enabled with application-default.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 01:54:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-issues-with-dropbox-traffic/m-p/246014#M70086</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-01-15T01:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID Issues with Dropbox traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-issues-with-dropbox-traffic/m-p/246102#M70104</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSL Decryption is not enabled.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;When you aren't decrypting traffic app-id is doing the best it can with the information it can see, which isn't much. So by its nature this means that application identification can be hit or miss.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 15:41:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-issues-with-dropbox-traffic/m-p/246102#M70104</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-15T15:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID Issues with Dropbox traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-issues-with-dropbox-traffic/m-p/246196#M70128</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;I think the problem is that the Dropbox Sync client uses a pinned certificate, so it actually cannot be decrypted by the firewall. OP wants to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can apply QoS based on IP address, app, and service, but none of those are really distinguishable here. You may need to use something like MindMeld or otherwise create an External Dynamic List object and use that for the QoS rule.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 01:06:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-issues-with-dropbox-traffic/m-p/246196#M70128</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-01-16T01:06:49Z</dc:date>
    </item>
  </channel>
</rss>

