<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How work App-id when trafic is not inspected in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-work-app-id-when-trafic-is-not-inspected/m-p/367012#M88786</link>
    <description>&lt;P&gt;Good morning all,&lt;BR /&gt;I have a question regarding the relationship between Appid and Ssl Decryption. How can the Fw recognize an application when the traffic is not inspected?&lt;BR /&gt;Example user request &lt;A href="https://www.youtube.com/watch?v=2zB2jiCxxuQ" target="_blank"&gt;https://www.youtube.com/watch?v=2zB2jiCxxuQ&lt;/A&gt;. What is the Fw going to see? The source ip, the destination ip for &lt;A href="http://www.youtube.com" target="_blank"&gt;www.youtube.com&lt;/A&gt; 142.250.74.238 the Fqdn &lt;A href="http://www.youtube.com" target="_blank"&gt;www.youtube.com&lt;/A&gt; and the certificate presented by the server which in our case is a multi san&lt;BR /&gt;* .google.com, *. android.com, *. appengine.google.com, source.android.google.cn, urchin.com, &lt;A href="http://www.goo.gl" target="_blank"&gt;www.goo.gl&lt;/A&gt;, youtu.be, youtube.com, youtubeeducation.com, youtubekids.com, yt.be and many more ...&lt;/P&gt;&lt;P&gt;In this case for me application recognition can only be based on FQDN and SANs is this correct? In this case App-id will be in "best effort" because it will not be able to recognize the signature of the application since the traffic is not inspected.&lt;BR /&gt;If my analysis is correct, does it really make sense to use App-Id in the rules when traffic is not inspected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For exemple for Starleaf traking&lt;BR /&gt;( port.dst eq 24704 ) and ( addr.dst in 88.84.147.242 )&lt;BR /&gt;Traffic To 88.84.147.242 is not decrypt du to exclusion&lt;BR /&gt;Recognized apps are&lt;BR /&gt;unknown-udp Drop&lt;BR /&gt;starleaf allow&lt;BR /&gt;insufficient-data allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2020 10:34:53 GMT</pubDate>
    <dc:creator>Antoinenucera</dc:creator>
    <dc:date>2020-12-03T10:34:53Z</dc:date>
    <item>
      <title>How work App-id when trafic is not inspected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-work-app-id-when-trafic-is-not-inspected/m-p/367012#M88786</link>
      <description>&lt;P&gt;Good morning all,&lt;BR /&gt;I have a question regarding the relationship between Appid and Ssl Decryption. How can the Fw recognize an application when the traffic is not inspected?&lt;BR /&gt;Example user request &lt;A href="https://www.youtube.com/watch?v=2zB2jiCxxuQ" target="_blank"&gt;https://www.youtube.com/watch?v=2zB2jiCxxuQ&lt;/A&gt;. What is the Fw going to see? The source ip, the destination ip for &lt;A href="http://www.youtube.com" target="_blank"&gt;www.youtube.com&lt;/A&gt; 142.250.74.238 the Fqdn &lt;A href="http://www.youtube.com" target="_blank"&gt;www.youtube.com&lt;/A&gt; and the certificate presented by the server which in our case is a multi san&lt;BR /&gt;* .google.com, *. android.com, *. appengine.google.com, source.android.google.cn, urchin.com, &lt;A href="http://www.goo.gl" target="_blank"&gt;www.goo.gl&lt;/A&gt;, youtu.be, youtube.com, youtubeeducation.com, youtubekids.com, yt.be and many more ...&lt;/P&gt;&lt;P&gt;In this case for me application recognition can only be based on FQDN and SANs is this correct? In this case App-id will be in "best effort" because it will not be able to recognize the signature of the application since the traffic is not inspected.&lt;BR /&gt;If my analysis is correct, does it really make sense to use App-Id in the rules when traffic is not inspected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For exemple for Starleaf traking&lt;BR /&gt;( port.dst eq 24704 ) and ( addr.dst in 88.84.147.242 )&lt;BR /&gt;Traffic To 88.84.147.242 is not decrypt du to exclusion&lt;BR /&gt;Recognized apps are&lt;BR /&gt;unknown-udp Drop&lt;BR /&gt;starleaf allow&lt;BR /&gt;insufficient-data allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 10:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-work-app-id-when-trafic-is-not-inspected/m-p/367012#M88786</guid>
      <dc:creator>Antoinenucera</dc:creator>
      <dc:date>2020-12-03T10:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: How work App-id when trafic is not inspected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-work-app-id-when-trafic-is-not-inspected/m-p/367258#M88818</link>
      <description>&lt;P&gt;the SNI is also used to help identify YouTube if you do not have ssl decryption enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unknown-udp would not be normally encrypted data and insufficient data mans there will probably only be 4 or 5 packets echsnged with no usable data to identify an application, you could set up a packetcapture to verify what this could be and either create a custom application, or submit the data to Palo Alto so the signature can be improved&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 09:33:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-work-app-id-when-trafic-is-not-inspected/m-p/367258#M88818</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-12-04T09:33:16Z</dc:date>
    </item>
  </channel>
</rss>

