App-ID Issues with Dropbox traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

App-ID Issues with Dropbox traffic

L4 Transporter

Hello,

 

We've got QoS setup on a PA-220 that classes any traffic marked with the dropbox App-ID. This class is then restricted to 2mbps. However we find that not all traffic generated by the Dropbox Sync client is marked as dropbox. Sometimes it's just ssl, sometimes its unknown-udp. Essentially we just want to restrict any Dropbox traffic to 2mbps through the Internet. 

How do we achieve this?

 

We are using Dropbox as an installed application (not from web browser).

SSL Decryption is not enabled.

The concerned policy has 'dropbox' application enabled with application-default.

 

 

1 accepted solution

Accepted Solutions

@BPry I think the problem is that the Dropbox Sync client uses a pinned certificate, so it actually cannot be decrypted by the firewall. OP wants to 

 

You can apply QoS based on IP address, app, and service, but none of those are really distinguishable here. You may need to use something like MindMeld or otherwise create an External Dynamic List object and use that for the QoS rule.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@FarzanaMustafa wrote:

 

SSL Decryption is not enabled. 


When you aren't decrypting traffic app-id is doing the best it can with the information it can see, which isn't much. So by its nature this means that application identification can be hit or miss. 

@BPry I think the problem is that the Dropbox Sync client uses a pinned certificate, so it actually cannot be decrypted by the firewall. OP wants to 

 

You can apply QoS based on IP address, app, and service, but none of those are really distinguishable here. You may need to use something like MindMeld or otherwise create an External Dynamic List object and use that for the QoS rule.

  • 1 accepted solution
  • 4076 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!