google not working with chrome update if unknown-udp is blocked

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

google not working with chrome update if unknown-udp is blocked

L3 Networker

Hi,

chrome version 54.0.2840.59m if unknown-udp is blocked - google is not working

 

Any idea ?

 

Thanks

 

1 accepted solution

Accepted Solutions

Chrome uses quic by default that runs over udp.

Probably they changed the behaviour and Palo AppID does not match any more.

 

Temporary workaround might be to disable quic in Chrome.

You can't decypt quic anyway so you loose visibility when users access Google services with Chrome so disabling it might be good idea anyway.

 

https://www.google.ee/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=chrome%20disable%20quic

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

9 REPLIES 9

Cyber Elite
Cyber Elite

@PanIst I can't reproduce the issue on my 3020. Did you recently install a new applications and threats update? I'm still on 621 until this evening and everything is working perfectly on 54.0.2840.59 m. 

Hi,

 

please use a deny rule for unknown-udp at top and app-id is 623

Tried with 3 paloalto(vm,5050 and pa200) same issue 

 

Regards

app-id version is not ipmportant.Tried with 614 and it is same.

@PanIst I'm not seeing the same issue; traffic is being identified correctly and nothing is getting denied because of the Chrome update. 

I'm sorry but there must be something different at your side.We replicated it on 3 different customer.Thanks

a.pngb.pngc.pngd.pnge.pngf.png

Chrome uses quic by default that runs over udp.

Probably they changed the behaviour and Palo AppID does not match any more.

 

Temporary workaround might be to disable quic in Chrome.

You can't decypt quic anyway so you loose visibility when users access Google services with Chrome so disabling it might be good idea anyway.

 

https://www.google.ee/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=chrome%20disable%20quic

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Had the same issue, Palo TAC advises that the content team is working to resolve the issue. Watch this space for an emergency release.

Version 625
Notes:
With the most recent version of the browser Chrome, Google updated their experimental protocol QUIC, which caused the "quic" App-ID to be misidentified as "unknown-udp". With this content update, Palo Alto Networks is releasing additional coverage for the "quic" App-ID to include the changes made by Google.

  • 1 accepted solution
  • 6900 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!