App-ID updates break existing rules

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

App-ID updates break existing rules

L3 Networker

Howdy,

How do most of you manage situations where App-ID updates break functioning rules?  This just happened to me: I have Lync 2010 and the internal clients need to connect to the edge server.  I had a rule in place that allowed ms-lync, ssl, and stun.  That worked fine until last weeks update (396), at which point ssl was now identified as "ms-lync-online".  So the rule started blocking traffic to external clients who shared a resource.  The fix was to observe internal client traffic to the Lync edge server to see that traffic was now denied, then add the application to the list of allowed traffic.

So that is one instance, I bet others out there have found issues too.  What are people doing to protect functioning policies from breaking after app-id updates?

Thanks,

Mike

8 REPLIES 8

L4 Transporter

What happens when a previously unknown App-ID gets added to PA through dynamic updates? How are othe... is a thread I started back in August asking this exact same question. All the answers were basically "use change control and monitor the App-IDs that get added."

How in the world we're expected to remember all the App-IDs in use and somehow just "know" that a new App-ID will identify traffic traversing our firewall I have no idea...

I guess for really business critical "it can never break" rules that you build, you can just use App-ID 'Any' and specific a port in the service column. That's the best thing I can come up with for rules that I build that "can't ever break."

L0 Member

Usually I experience this after my first commit.  Usually it is a scramble to quickly put in the new applications to unbreak things before people find out.

L3 Networker

Thanks for the reply's.  I guess I'm not alone on this.

@PAN - you need to figure out a way to merge these databases without breaking production environments.  My devices are in a data center, so it isn't pretty when something like this happens.

Mike

L4 Transporter

Welcome to my world.

I got bitten by the exact same update - broke my MS-Lync implementation - and added a metric shitload of dependencies into the rule for accessing the edge server from outside.

Best you can do is subscribe to the upgrade notifications, and check every single one before applying the content upgrade. I don't allow my firewall to auto-apply content updates (virus and web filtering fine, but not content) for exactly this reason.

PAN are kind of between a rock and a hard place here - people want new apps identified to give better control - but they can't do that without breaking some older implementations which were basically work-arounds because the app wasn't identified.

Maybe some kind of pre-parsing of content upgrades which checks against affected rules and notifies before applying - like they do if you try and delete an object which is referenced elsewhere - but I don't know how feasible this would be, especially if you've got a lot of rules to check against.

+1

If they broke out App-ID updates from threat updates that would be nice too. I'd like to not be missing threat updates that have come out just because I'm holding off on updating my App-ID version... right now the two are intertwined. I'd rather see them split apart.

L5 Sessionator

Hi Mike,

You can always go to the release notes before upgrading. That will have the modified decoders and the latest added or changed applications.

Thank you

Numan

This is about the best option and best description of the circumstances

  • 4866 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!