11-06-2012 03:09 AM
Hi,
I've some problems with skype instant messaging.
Sometimes the messages are not sent.
Checking firewall logs I see when messages are not sent an 'unknown-tcp' connection is denied.
Same destination port (but different ip) were used and recognized before as 'skype' connection
For example
Time | App | From | Src Port Source |
Rule | Action | To | Dst Port Destination |
Src User | Dst User |
===============================================================================
2012/11/06 11:19:26 skype | Zone1 52682 | 192.168.xxx.xxx | ||
Skype | allow | Zone2 | 12350 | 78.141.179.16 |
user1 |
2012/11/06 11:19:56 unknown-tcp | Zone1 49727 | 192.168.xxx.xxx |
blocca_navigazione deny | Zone2 12350 | 78.141.179.12 |
user1 |
It seems that PAN-OS was not able to identify correctly the connection.
For security reasons I cannot open 'unknown-tcp' connection.
Any solutions?
Firewall PAN-500
OS: 4.1.7
Application and threat: 336-1565 2012-10-30
Thanks
Regards
11-08-2012 07:23 AM
Hi,
after I allowed "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports) everything works fine.
I see "unknow-tcp" traffic so problem is that some skype packets are not correctly recognized.
I will open a support case
11-06-2012 04:04 AM
I wonder if the dependency fixes in PANOS 5.0 would help you or not.
I mean this way only enough traffic to identify what you have set to allow will be able to pass through.
In this particular case this would hopefully mean that "unknown-tcp" would be allowed for x packets going from this particular client towards wathever ip/port the signature for skype in appid uses (compared to today where you basically must allow "unknown-tcp" statically with srcip:any dstip:any unless you want stuff like this to be blocked).
By the way, did you already enable skype-probe?
11-06-2012 05:42 AM
Hi,
skype-probe is enable.
Now I'm testing a new rule for this user.
I'm allowing "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports).
Probably it will works but problem is that I want keep blocked "unknown-tcp" from any to any...
Do you know if PAN OS 5.0 will solve this problem? When will the new version?
Thanks
Regards
11-06-2012 11:05 AM
Hi Mauro,
If you still see Skype traffic being classified incorrectly I would suggest opening a support case so we can investigate. We will likely need a client PCAP and the show session output showing the problem sessions but we should be able to add it to the application.
Thanks,
-- Kevin
11-08-2012 07:23 AM
Hi,
after I allowed "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports) everything works fine.
I see "unknow-tcp" traffic so problem is that some skype packets are not correctly recognized.
I will open a support case
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!