How work App-id when trafic is not inspected

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

How work App-id when trafic is not inspected

L0 Member

Good morning all,
I have a question regarding the relationship between Appid and Ssl Decryption. How can the Fw recognize an application when the traffic is not inspected?
Example user request What is the Fw going to see? The source ip, the destination ip for the Fqdn and the certificate presented by the server which in our case is a multi san
*, *., *.,,,,,,,, and many more ...

In this case for me application recognition can only be based on FQDN and SANs is this correct? In this case App-id will be in "best effort" because it will not be able to recognize the signature of the application since the traffic is not inspected.
If my analysis is correct, does it really make sense to use App-Id in the rules when traffic is not inspected?


For exemple for Starleaf traking
( port.dst eq 24704 ) and ( addr.dst in )
Traffic To is not decrypt du to exclusion
Recognized apps are
unknown-udp Drop
starleaf allow
insufficient-data allow



Cyber Elite
Cyber Elite

the SNI is also used to help identify YouTube if you do not have ssl decryption enabled


unknown-udp would not be normally encrypted data and insufficient data mans there will probably only be 4 or 5 packets echsnged with no usable data to identify an application, you could set up a packetcapture to verify what this could be and either create a custom application, or submit the data to Palo Alto so the signature can be improved



Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!