Skype-Probe sessions increase dramtically when blocking skype

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Skype-Probe sessions increase dramtically when blocking skype

L0 Member

Hi All,

Seem to be having a bit of a problem with skype-probe.

I have a PA-500 in Vwire mode behind a PIX FW, the customer wishes to block Skype traffic.

Observations:

1.     On the ACC the ammount of skype-probe traffic far exceedes any other traffic in terms of sessions

2.     The ammount of bytes of skype-probe traffic is roughly in relation to the amount of skype bytes

3.     When enabling a skype only block rule (still allowing skype-probe) the active session count sky rockets

The sessions that increase dramatically are from skype-probe these sessions go from a current 4,000 sessions to 50,000+ in a matter of under a minute until the skype block rule is disabled.

Any help and insight will be greatly appreciated

Cheers

Marc

attached is screen shots of skype-probe session count for last hour

6 REPLIES 6

Not applicable

Please reference the "Controlling Skype" document in knowledge point from the support.paloaltonetworks.com support portal. 

L3 Networker

My understanding is that you need to allow skype-probe traffic through to establish a connection, and then block the actual skype traffic once the Skype client believes it has connected. This prevents Skype from going evasive, but it does create a confusing situation on the client where it appears to be connected successfully, yet calling does not actually work.

skype-robe is allowed in a rule.

The rule set look like this:

Source Zone
Dest ZoneSourceDest
Source User
Application
Service
Action
TrustUntrustanyanyanyskypeanydeny
TrustUntrustanyanyKnown UsersVarious Apps (Incl skype-probe)anyallow

Before skype is disabled the session count for skype-proble is high, as soon as you deny skype on the PA the skype-probe sessions go through the roof, as said earlier from about 4k sessions to 40k sessions in seconds.

try setting the allow skype-probe rule before the block skype rule, this may help decrease the number of probe connections

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

will give it a go and provide feedback once done.

Regards

Marc

Hi,

With a skype-probe allow rule above the skype block rule, we still experience the same volume of sessions

Marc

  • 6223 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!