Application bit-internal cannot be allowed.

Reply
Highlighted
Not applicable

Application bit-internal cannot be allowed.

How can I allow application bit-internal in my policy? This application is blocked by last rule (explicity block rule). I didn't see application bit-internal in my Object->application database and I can't use it in policy. We have PANOS 4.0.8 and application update 289-1268.

Community Team Member

Re: Application bit-internal cannot be allowed.

it Lists out the Application Depenencies, and "bit-internal" is dependant on "Web-browsing".

Is that part of the last rule"?

regards,

Stay Secure,
Joe
End of line
Not applicable

Re: Application bit-internal cannot be allowed.

I read this document. But I want to know why I can not choose the applications 'bit-internal' when creating policy. Even if the application 'web-browsing' is allowed my traffic is still blocked  'bit-internal'.

L6 Presenter

Re: Application bit-internal cannot be allowed.

Hmm... "bit-internal" isnt available on http://apps.paloaltonetworks.com/applipedia/ either (which I suppose contains latest app-id db?)

Edit: Did it perhaps get merged into "bittorrent" or some other appid? Because if you look at the dependecy document "bit-internal" is just before "bittorrent" comparing to "gnutella-internal" which is next to "gnutella".

Not applicable

Re: Application bit-internal cannot be allowed.

Yes. On device I have latest app-id database, too. There is no 'bit-internal' in Objects -> application, but ... when traffic is analyzed logs show application 'bit-internal'.

L3 Networker

Re: Application bit-internal cannot be allowed.

internal apps:

This app is reported as bittorrent on the UI. This is what is going to happen for bittorrent:

1.       UDP sessions comes
2.      App id detects that it is bit-internal. It gets reported as bittorrent on UI
3.      App becomes bit-internal
4.      Bit-internal decoder runs
5.      It predicts TCP session
6.      It sets the app to bittorrent
7.      The session gets blocked if the action is deny for bittorrent
8.      TCP session arrives, and it becomes bittorrent, as expected


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!