AnyDesk application is not recognised in Palo Alto version 10.2.17

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

AnyDesk application is not recognised in Palo Alto version 10.2.17

L4 Transporter

Hello, team:

The AnyDesk application is not recognised in Palo Alto version 10.2.17; it is classified as SSL and I cannot block it.

Does anyone know if this is a problem with Palo Alto?

I don't have any decryption policies, In my company, we can only block this through apps by policy. . Can anyone help me?

Best regards

5 REPLIES 5

Cyber Elite
Cyber Elite

@Alpalo Under Objects, Application do search for AnyDesk app see if it shows up.

If decryption is not enabled, then firewall will see the application as ssl if it is using port 443.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

Is there no way for the AnyDesk app to be recognised unless we decrypt it?

Is there no way for the AnyDesk app to be recognised unless we decrypt it?

Community Team Member

Hi @Alpalo ,

 

AnyDesk is placed in the Do Not Decrypt Policy by default (Device > Certificate Management > SSL Decryption Exclusion). That said, App-ID should still work by inspecting the initial TLS handshake (Server Hello, SNI, certificate details) to identify the application as anydesk-base.

 

First, since the client software may have recently changed, please confirm that your firewall has the latest Application and Threat Content updates installed. This is the most common reason for application misidentification.

 

If the issue persists after updating the content, it suggests either a potential bug or a conflict with a custom policy. Before escalating to TAC, it is worth reviewing the community fix for related AnyDesk issues:

https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anyd...

https://live.paloaltonetworks.com/t5/general-topics/anydesk-issue/m-p/516607#M107283

 

Reading these discussions, the recurring fix for AnyDesk connectivity problems (when the connection breaks) involves importing the latest AnyDesk Root CA. Although this is primarily to solve certificate trust errors, the lack of trust can sometimes prevent the App-ID engine from fully resolving the certificate chain metadata, causing the session to fall back to the generic ssl identity.

 

It may be necessary to import the latest AnyDesk Root CA and mark it as a trusted certificate to allow App-ID to fully process the handshake and correctly identify the traffic.

 

Kind regards,

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Thank you for your reply, @kiwi, but the problem is that the FW detects Anydesk as SSL instead of ANYDESK.

How I can import the trust certificate?

Regards

 

  • 577 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!