<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting intermittent unknown UDP traffic logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/340942#M85545</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104297"&gt;@deepak12&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;What type of traffic are you actually seeing this on? It wouldn't be uncommon to see something developed internally have an unknown-tcp/udp determination, but if it's traversing the untrust/internet interface that's different.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In any case, it usually means that the firewall either didn't pass enough traffic to identify the app-id, or an app-id simply doesn't exist for the traffic.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2020 20:47:16 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-07-27T20:47:16Z</dc:date>
    <item>
      <title>Getting intermittent unknown UDP traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/340921#M85540</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having policy&amp;nbsp; having application group and set services as application default .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometime policy is working fine but sometime its dropping packet and in logs showing application&amp;nbsp; unknown UDP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please suggest any troubleshooting steps here ? I did packet capture but not seeing any this specific which can indicate any issue on firewall end .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 19:02:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/340921#M85540</guid>
      <dc:creator>deepak12</dc:creator>
      <dc:date>2020-07-27T19:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting intermittent unknown UDP traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/340942#M85545</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104297"&gt;@deepak12&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;What type of traffic are you actually seeing this on? It wouldn't be uncommon to see something developed internally have an unknown-tcp/udp determination, but if it's traversing the untrust/internet interface that's different.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In any case, it usually means that the firewall either didn't pass enough traffic to identify the app-id, or an app-id simply doesn't exist for the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 20:47:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/340942#M85545</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-27T20:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Getting intermittent unknown UDP traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/340950#M85547</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;It's syslog traffic . Moreover for same set of source and destination IP , its working fine , properly identifying the APP-id.&lt;/P&gt;&lt;P&gt;I am using default syslog app-id .&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 20:58:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/340950#M85547</guid>
      <dc:creator>deepak12</dc:creator>
      <dc:date>2020-07-27T20:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Getting intermittent unknown UDP traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/341076#M85582</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104297"&gt;@deepak12&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Interesting. I've never actually had the firewall fail to identify syslog traffic across the default 514 port, but I have if I customize the port without creating a custom application or doing an application-override see it come across as unknown-udp.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I would take a packet capture of the traffic when it comes across as unknown-udp and see if you can notice any sort of difference with the traffic. If you aren't seeing anything I would try to capture the traffic and open up a TAC case for review.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 16:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/341076#M85582</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-28T16:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Getting intermittent unknown UDP traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/341131#M85598</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks , I will check with Tac and update here with findings .&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 21:10:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-intermittent-unknown-udp-traffic-logs/m-p/341131#M85598</guid>
      <dc:creator>deepak12</dc:creator>
      <dc:date>2020-07-28T21:10:31Z</dc:date>
    </item>
  </channel>
</rss>

