<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does it identify unknown application where about flow logic? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-it-identify-unknown-application-where-about-flow-logic/m-p/10571#M7786</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello akawimandan~&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I told me,,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;For applications changing from one to another, Identification is done via protocol decoding in content inspection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as I know that PA has two engine(App-id, Content)&lt;/P&gt;&lt;P&gt;When Someone connect facebook, Does always PA flow Content Engine,,?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and than also I have another question~&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I guess that&amp;nbsp; unknown-tcp, unknown-udp, or non-syn-tcp.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Finally, When PA check Heuristic Engine to know application&lt;/P&gt;&lt;P&gt;eventually PA doesn't find application&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the traffic return to check [application signatures]?&lt;/P&gt;&lt;P&gt;because, I think so, There are &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;unknown-tcp, unknown-udp, or non-syn-tcp&lt;/SPAN&gt; signatures&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;^_^;;; I don't know exactly App-id Engine&lt;/P&gt;&lt;P&gt;I am also used to red uploaded documents by you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 08 Sep 2013 00:41:41 GMT</pubDate>
    <dc:creator>SilverTiger</dc:creator>
    <dc:date>2013-09-08T00:41:41Z</dc:date>
    <item>
      <title>How does it identify unknown application where about flow logic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-it-identify-unknown-application-where-about-flow-logic/m-p/10569#M7784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone;~&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very curious&lt;/P&gt;&lt;P&gt;refer to bottom image~&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is the unknown application where?&lt;/P&gt;&lt;P&gt;I guess that PA App-id check application signatures for the first time&lt;/P&gt;&lt;P&gt;and than If PA doesn't know app, PA App-id might move Heuristics engine;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and If PA try what could be checked at the engine;;&lt;/P&gt;&lt;P&gt;Does PA change unknown-tcp or unknow-udp?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't been lookup any document about unknow application flow logic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T-T&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="8092" alt="이미지 1.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8092_이미지 1.png" style="width: 620px; height: 351px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Sep 2013 11:45:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-it-identify-unknown-application-where-about-flow-logic/m-p/10569#M7784</guid>
      <dc:creator>SilverTiger</dc:creator>
      <dc:date>2013-09-07T11:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: How does it identify unknown application where about flow logic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-it-identify-unknown-application-where-about-flow-logic/m-p/10570#M7785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pattern-Based Application Identification occurs in the App_ID Engine.&lt;/P&gt;&lt;P&gt;If a matching signature is not found in the Application Database the Application is identified as either unknown-tcp, unknown-udp, or non-syn-tcp.&lt;/P&gt;&lt;P&gt;For applications changing from one to another, Identification is done via protocol decoding in content inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For detailed Packet Flow :Refer&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1628"&gt;Packet Flow in PAN-OS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;See Also :&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2007"&gt;Unknown Applications&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Sep 2013 15:08:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-it-identify-unknown-application-where-about-flow-logic/m-p/10570#M7785</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-09-07T15:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: How does it identify unknown application where about flow logic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-it-identify-unknown-application-where-about-flow-logic/m-p/10571#M7786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello akawimandan~&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I told me,,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;For applications changing from one to another, Identification is done via protocol decoding in content inspection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as I know that PA has two engine(App-id, Content)&lt;/P&gt;&lt;P&gt;When Someone connect facebook, Does always PA flow Content Engine,,?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and than also I have another question~&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I guess that&amp;nbsp; unknown-tcp, unknown-udp, or non-syn-tcp.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Finally, When PA check Heuristic Engine to know application&lt;/P&gt;&lt;P&gt;eventually PA doesn't find application&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the traffic return to check [application signatures]?&lt;/P&gt;&lt;P&gt;because, I think so, There are &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;unknown-tcp, unknown-udp, or non-syn-tcp&lt;/SPAN&gt; signatures&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;^_^;;; I don't know exactly App-id Engine&lt;/P&gt;&lt;P&gt;I am also used to red uploaded documents by you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Sep 2013 00:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-it-identify-unknown-application-where-about-flow-logic/m-p/10571#M7786</guid>
      <dc:creator>SilverTiger</dc:creator>
      <dc:date>2013-09-08T00:41:41Z</dc:date>
    </item>
  </channel>
</rss>

