iperf is always matched as unknown-udp/tcp

Reply
L2 Linker

iperf is always matched as unknown-udp/tcp

Is there any reason why iperf traffic in either TCP or UDP is recognised as unknown-udp/tcp by the PAFW?

 

there is an app-id called 'iperf' but it never matches.

L4 Transporter

Re: iperf is always matched as unknown-udp/tcp

I just tried it using the iperf3 64 bit windows binaries from https://iperf.fr/iperf-download.php and it matches on 8.0.1

Capture.JPG

 

 can you offer more specifics on what you're using?

 

 

--
CCNA Security, PCNSE7
L2 Linker

Re: iperf is always matched as unknown-udp/tcp

jperf  2.0.2

PAN-OS 7.1.7

 

testing with iperf now, however it shouldnt be any different as jperf is just a Java frontend.

L6 Presenter

Re: iperf is always matched as unknown-udp/tcp

Can you please post the detailed traffic logs.

L4 Transporter

Re: iperf is always matched as unknown-udp/tcp

same result for me using jperf2.0.2 from the Google Code archive. your app/threat content is current? you are using the default port of 5001?

 

Capture.JPG

 

 

 

 

--
CCNA Security, PCNSE7
L2 Linker

Re: iperf is always matched as unknown-udp/tcp

Untitled.png

L6 Presenter

Re: iperf is always matched as unknown-udp/tcp

Some users did report weird stuff with app-id before so wondering if you can create a separate policy to allow iperf only as an application and test again.

L2 Linker

Re: iperf is always matched as unknown-udp/tcp

I thought the same as well, and ran that test with rule #1 being an iperf app-id rule

L6 Presenter

Re: iperf is always matched as unknown-udp/tcp

Getting interesting isn't it :0 Reinstall app-id database possible in your environment? I guess this is the only one app at the moment that is not identified correctly?

L2 Linker

Re: iperf is always matched as unknown-udp/tcp

yea i can reinstall, its also the 2nd firewall in a completely different environment that ive seen this on.

 

yes, only iperf for now

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!