<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User is trying to connect with MS-RDP.  Log shows TCP 3389 but application is not-applicable in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-is-trying-to-connect-with-ms-rdp-log-shows-tcp-3389-but/m-p/428276#M94695</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136122"&gt;@FrankMurray&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So MS-RDP implicitly uses COTP and t.120, but I've actually found that the firewall sometimes doesn't actually allow the traffic if COTP isn't specifically specified and will at times drop the COTP traffic. As a test, add COTP as an application member on this security entry and have the user try again.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 22 Aug 2021 04:13:41 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-08-22T04:13:41Z</dc:date>
    <item>
      <title>User is trying to connect with MS-RDP.  Log shows TCP 3389 but application is not-applicable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-is-trying-to-connect-with-ms-rdp-log-shows-tcp-3389-but/m-p/428213#M94688</link>
      <description>&lt;P&gt;We've got a remote user connecting with GlobalProtect.&amp;nbsp; He's trying to RDP to a PC on our inside network.&amp;nbsp; There is a security policy that he should be matching-&amp;nbsp; traffic matches source and destination zones, user-ID is matching the right group,&amp;nbsp; HIP check is good.&amp;nbsp; it seems to be failing to match the policy because it's not matching on the application.&amp;nbsp; The user is using MS-RDP and the traffic is showing up on TCP port 3389.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 22:23:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-is-trying-to-connect-with-ms-rdp-log-shows-tcp-3389-but/m-p/428213#M94688</guid>
      <dc:creator>FrankMurray</dc:creator>
      <dc:date>2021-08-20T22:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: User is trying to connect with MS-RDP.  Log shows TCP 3389 but application is not-applicable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-is-trying-to-connect-with-ms-rdp-log-shows-tcp-3389-but/m-p/428276#M94695</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136122"&gt;@FrankMurray&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So MS-RDP implicitly uses COTP and t.120, but I've actually found that the firewall sometimes doesn't actually allow the traffic if COTP isn't specifically specified and will at times drop the COTP traffic. As a test, add COTP as an application member on this security entry and have the user try again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 04:13:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-is-trying-to-connect-with-ms-rdp-log-shows-tcp-3389-but/m-p/428276#M94695</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-08-22T04:13:41Z</dc:date>
    </item>
  </channel>
</rss>

