Identifying Applications

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Identifying Applications

L3 Networker

Hi guys,

 

Got an odd one here. Traffic is being identified as a completely different application to what the traffic actually is. For example, see below.

 

traffic application.png

I've cleared the dataplane cache and re-downloaded the DB categorisation as per the document below, but to no avail.

 

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Handle-a-URL-Miscategorization/ta-p/...

 

Anyone experienced this before? Device is running 7.1.2 and apps and threats are up to date.

 

Cheers

Jack

 

3 REPLIES 3

L5 Sessionator

what do you see when you run the command

test url <URL>

L5 Sessionator

You can also try:

 

debug dataplane reset appid cache

Hi Pankaj,


Thanks for your reponse.

 

I have tried all of this to no avail. It looks like a buggy app-id engine.

 

If I apply the URL filtering profile to the policy the issue occurs, however if there isn't a URL filtering profile, and I check the traffic logs, the application is identified correctly.

 

This case is being escalated to a higher tier for now. Just in case anyone experiences the same issue, I will update this as the case progresses and interesting information comes in.


Cheers

Jack

  • 2124 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!