- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-21-2013 11:44 PM
Hello guys,
About skype: how to know, when users realy use skype and when PA detects only false positive? Because now i have lot of log with "secure.skype.com" URL and PA detects it as skype application.. I would be grateful for an explanation.
08-23-2013 04:11 AM
Explanation:
if the webpage contains a java script "detection_as3.swf", wich redirects to webpage "https://secure.skype.com", PA firewall this connection consider as a "skype" application. Case closed.
08-22-2013 12:31 AM
Hi Ignas,
Users are using any other video/audio calling application into their machine...? Please follow below mentioned documents for more information about SKYPE.
Also I would recommend you to open a case with support.
Thanks
08-22-2013 02:07 AM
Skype not installed on users' computers. We checked this. But PA detects skype application. Detailed log shows "secure.skype.com" URL.
08-22-2013 02:13 AM
Could be a false positive. Is the firewall on the latest dynamic updates ?
08-22-2013 02:56 AM
Hi
The URL log as below is generated by accessing to secure.skype.com from IE10.
Do you mean you can't figure out this is actual skype session or just https session from browser?
If my understanding is correct, I guess there is no clue to figure out which pattern is it because the session is encrypted by ssl and PaloAlto device could not see the payload.
However, skype client send out skype-probe session, if you can see skype and skype-probe from one source address, you might be able to say that user is using skype client.
Regards
08-22-2013 04:12 AM
Hi emr,
many thanks for your answer. I can't find skype-probe. So no skype client is being used. I think that users are redirected to a "secure.skype.com" page from some other page or something like that, though I can't say exactly. Because when I type in a web browser "secure.skype.com", i'm redirected to "login.skype.com" and PA log shows few records "secure.skype.com", "login.skype.com" and "apps.skypeassets.com". And when I look at users log, I only see "secure.skype.com" records. I'm trying to figure out how this happens.
08-22-2013 04:35 AM
If the user is using skype client, you can find skype-probe in traffic log as below:
I can see all URLs you mentioned. (URL category name might be different from you because I'm using PAN-DB instead of BrightCloud)
What is 'users log' you are pointing to?
Do you mean detail log for 'secure.skype.com'?
08-22-2013 05:07 AM
URL log. I use filter: (url contains skype).
08-22-2013 05:48 AM
Well, it looks like your PaloAlto device places between client PC and proxy server.
I'm not using proxy. This might causes different result.
08-22-2013 06:31 AM
Maybe. Anyway thank you for help
08-23-2013 04:11 AM
Explanation:
if the webpage contains a java script "detection_as3.swf", wich redirects to webpage "https://secure.skype.com", PA firewall this connection consider as a "skype" application. Case closed.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!