Identifying Applications

Reply
L3 Networker

Identifying Applications

Hi guys,

 

Got an odd one here. Traffic is being identified as a completely different application to what the traffic actually is. For example, see below.

 

traffic application.png

I've cleared the dataplane cache and re-downloaded the DB categorisation as per the document below, but to no avail.

 

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Handle-a-URL-Miscategorization/ta-p/...

 

Anyone experienced this before? Device is running 7.1.2 and apps and threats are up to date.

 

Cheers

Jack

 

L5 Sessionator

what do you see when you run the command

test url <URL>

L5 Sessionator

You can also try:

 

debug dataplane reset appid cache

L3 Networker

Hi Pankaj,


Thanks for your reponse.

 

I have tried all of this to no avail. It looks like a buggy app-id engine.

 

If I apply the URL filtering profile to the policy the issue occurs, however if there isn't a URL filtering profile, and I check the traffic logs, the application is identified correctly.

 

This case is being escalated to a higher tier for now. Just in case anyone experiences the same issue, I will update this as the case progresses and interesting information comes in.


Cheers

Jack

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!