x.com website api calls classified as twitter-messaging

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

x.com website api calls classified as twitter-messaging

L2 Linker

Starting a week or two ago one of my customers started experiencing website issues with x.com. Their current environment allows application "twitter-base" but not "twitter-messaging". It appears that with a recent content update Palo now classifies the internal x.com website api calls as "twitter-messaging" which my customer blocks causing the page to not load. My customer has been blocking "twitter-messaging" for years with no issues. Not until a week or two did the access to x.com break.

 

Anyone else have this issue and resolution?

1 REPLY 1

Cyber Elite
Cyber Elite

You can make a custom app signature based on the host url and a new rule before the blocking rule that allows the custom app limiting the rule to only allowed source ip and the destination servers that host the  internal x.com website. Have you seen my article How to Write Palo Alto Networks Custom Vulnerability and Application Signatures with Examples ?

 

Outside of that there are other ways as well as allowing traffic for "twitter-messaging" based on the destination url/fqdn and again only for the needed source and destination IP addresses or even App bypass that I don't recommend as that is final solution Tips & Tricks: How to Create an Application Override - Knowledge Base - Palo Alto Networks Maybe you can try to place app overide after the twitter base rule as to stop the app identification for "twitter-messaging" as there should be application shift for palo alto to identify again the traffic from base to messaging but it could have mixed results. For app shift see :

 

Application Shift and How to allow linkedIn but block specific linkedin-posting application

 

How to Prevent Application Shift - Knowledge Base - Palo Alto Networks

 

Tips & Tricks: App-ID Debugging

  • 329 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!