PA apps

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PA apps

L4 Transporter

Hi,

 

We are expecting problem with PA identifying apps.

We have sessions in port 13000 being identified as play-station network. These sessions are not related to Pstation.

 

On the another hand, we also have sessions in port 80 being identified as unknown-tcp.

 

why PA is idenfitying like this?? how can we solve this app problem??

 

2 REPLIES 2

L6 Presenter

You can get PCAP  from these sessions as well as try to reinstall newer app-database or even reinstall already existing one.  But be honest, not sure what is going on. 

Cyber Elite
Cyber Elite

@soporteseguridad,

unknown-tcp sessions are fairly common and are exactly that, usually it's because the session didn't actually process enough traffic to identify the app-id or the app-id simply doesn't exist. 

The playstation-network identification is odd simply because the application doesn't actually use that port range by default. My guess is that you are not decrypting the traffic and therefore the firewall is trying it's best but will have false-positives or miss app-ids at times simply based off of how the feature functions and the amount of information it can see with the information it has access to without SSL decryption enabled. 

 

As @TranceforLife stated the best course of action would be taking PCAPs and attempting to figure out what the traffic actually is. If the traffic is known you can build out a custom application signature to identify the traffic correctly and if you can identify it further you can pass the infromation along so that Palo Alto can attempt to narrow the application signature if at all possible so it's not flagging traffic incorrectly. 

  • 1623 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!