- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-06-2012 03:09 AM
Hi,
I've some problems with skype instant messaging.
Sometimes the messages are not sent.
Checking firewall logs I see when messages are not sent an 'unknown-tcp' connection is denied.
Same destination port (but different ip) were used and recognized before as 'skype' connection
For example
Time | App | From | Src Port Source |
Rule | Action | To | Dst Port Destination |
Src User | Dst User |
===============================================================================
2012/11/06 11:19:26 skype | Zone1 52682 | 192.168.xxx.xxx | ||
Skype | allow | Zone2 | 12350 | 78.141.179.16 |
user1 |
2012/11/06 11:19:56 unknown-tcp | Zone1 49727 | 192.168.xxx.xxx |
blocca_navigazione deny | Zone2 12350 | 78.141.179.12 |
user1 |
It seems that PAN-OS was not able to identify correctly the connection.
For security reasons I cannot open 'unknown-tcp' connection.
Any solutions?
Firewall PAN-500
OS: 4.1.7
Application and threat: 336-1565 2012-10-30
Thanks
Regards
11-08-2012 07:23 AM
Hi,
after I allowed "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports) everything works fine.
I see "unknow-tcp" traffic so problem is that some skype packets are not correctly recognized.
I will open a support case
11-06-2012 04:04 AM
I wonder if the dependency fixes in PANOS 5.0 would help you or not.
I mean this way only enough traffic to identify what you have set to allow will be able to pass through.
In this particular case this would hopefully mean that "unknown-tcp" would be allowed for x packets going from this particular client towards wathever ip/port the signature for skype in appid uses (compared to today where you basically must allow "unknown-tcp" statically with srcip:any dstip:any unless you want stuff like this to be blocked).
By the way, did you already enable skype-probe?
11-06-2012 05:42 AM
Hi,
skype-probe is enable.
Now I'm testing a new rule for this user.
I'm allowing "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports).
Probably it will works but problem is that I want keep blocked "unknown-tcp" from any to any...
Do you know if PAN OS 5.0 will solve this problem? When will the new version?
Thanks
Regards
11-06-2012 11:05 AM
Hi Mauro,
If you still see Skype traffic being classified incorrectly I would suggest opening a support case so we can investigate. We will likely need a client PCAP and the show session output showing the problem sessions but we should be able to add it to the application.
Thanks,
-- Kevin
11-08-2012 07:23 AM
Hi,
after I allowed "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports) everything works fine.
I see "unknow-tcp" traffic so problem is that some skype packets are not correctly recognized.
I will open a support case
11-08-2012 07:29 AM
Also keep in my mind that Skype is one the of the most tricky and hiding application and it changes often. The fact it's seen as unknown-tcp is not surprise and can't blame PAN for this.
Skype should document their product and stop playing cat and mouse game if they don't want to be purely blocked in all big corp networks.
11-08-2012 07:40 AM
I know Skype changes very often and I understand that it shouldn't be simple for PAN.
I think problem is that sometimes destination IP changes.
I paste again my above example:
Time | App | From | Src Port Source |
Rule | Action | To | Dst Port Destination |
Src User | Dst User |
===============================================================================
2012/11/06 11:19:26 skype | Zone1 52682 | 192.168.xxx.xxx | ||
Skype | allow | Zone2 | 12350 | 78.141.179.16 |
user1 |
2012/11/06 11:19:56 unknown-tcp | Zone1 49727 | 192.168.xxx.xxx |
blocca_navigazione deny | Zone2 12350 | 78.141.179.12 |
user1 |
As you can see in the first line the IP was 78.141.179.16 (destination port 12350 ) while in the second line IP was 78.141.179.12 (same destination port)...
By the way...
Yesterday PAN sent
Version 337
Risk | Name | Category | Subcategory | Technology | Depends on | Minimum Version |
4 | flash | general-internet | internet-utility | browser-based | web-browsing |
|
3 | hotspot-shield | networking | encrypted-tunnel | client-server | ssl,web-browsing |
|
5 | nntp | general-internet | internet-utility | client-server |
| |
1 | pcoip | networking | remote-access | client-server |
| |
2 | securid | business-systems | auth-service | client-server |
| |
4 | skydrive(function) | general-internet | file-sharing | browser-based | live-mesh,ssl,web-browsing |
|
5 | skype | collaboration | voip-video | peer-to-peer | web-browsing |
|
Skype application changed.
Do you know if PAN solved this problem?
Thanks
Regards
11-08-2012 07:45 AM
IPs will change all time : Skype is not a centralized system , a client (you for example) can become a proxy for other clients, like a peer to peer program. Same when you chat / video call, it's a peer to peer communication.
Also you can revert to the old signature package and see if it solves your problems.
11-08-2012 07:48 AM
So you think this cannot be the problem, don't you?
11-08-2012 07:49 AM
That's my opinion: Destination IP and ports cannot be the problem as Skype is peer to peer enabled it doesn't rely on a pre-known list of servers.
11-08-2012 07:51 AM
Try to revert to an old signature package (you were suggesting this is happening since version 337)
11-08-2012 07:59 AM
No: I were suggesting it could be solved with this new version 337 released yesterday (I apologize for my English)
The problem occurs for several weeks
11-08-2012 08:02 AM
Well yes you should try new signature, especially if it says Skype signature was updated.
My advice would be to forbid Skype on your network anyway : it's peer to peer, encrypted (so anti virus/vulnerability cannot do its job), its code was accessed by many many developpers/hackers over the years/buyouts . to make it short, it's all but secure or 'securable'.
11-08-2012 08:28 AM
I cannot.... Too many customers use it... So we need Skype...
11-08-2012 09:03 AM
Then I advice you to add 'unknown-tcp' when customers start complaining until PA releases a fix.
I have another application that is creating me such problems, 4 or 5 times per year the protocol changes a bit and PAN releases a fix after a few weeks, during that time I have no other choice than allow unkown-tcp until the fix is there.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!