Skype IM Problem

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Skype IM Problem

L3 Networker

Hi,

I've some problems with skype instant messaging.

Sometimes the messages are not sent.

Checking firewall logs I see when messages are not sent an 'unknown-tcp' connection is denied.

Same destination port (but different ip) were used and recognized before as 'skype' connection

For example

Time            App         From        Src Port   Source
Rule            Action      To          Dst Port   Destination
                Src User    Dst User

===============================================================================

2012/11/06 11:19:26 skype       Zone1      52682 192.168.xxx.xxx
Skype           allow       Zone212350 78.141.179.16
                user1

2012/11/06 11:19:56 unknown-tcp Zone1  49727 192.168.xxx.xxx
blocca_navigazione  deny        Zone2   12350 78.141.179.12
                user1

It seems that PAN-OS was not able to identify correctly the connection.

For security reasons I cannot open 'unknown-tcp' connection.

Any solutions?

Firewall PAN-500

OS: 4.1.7

Application and threat:  336-1565 2012-10-30

Thanks

Regards

1 ACCEPTED SOLUTION

Accepted Solutions

Hi,

after I allowed "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports) everything works fine.

I see "unknow-tcp" traffic so problem is that some skype packets are not correctly recognized.

I will open a support case

View solution in original post

40 REPLIES 40

L6 Presenter

I wonder if the dependency fixes in PANOS 5.0 would help you or not.

I mean this way only enough traffic to identify what you have set to allow will be able to pass through.

In this particular case this would hopefully mean that "unknown-tcp" would be allowed for x packets going from this particular client towards wathever ip/port the signature for skype in appid uses (compared to today where you basically must allow "unknown-tcp" statically with srcip:any dstip:any unless you want stuff like this to be blocked).

By the way, did you already enable skype-probe?

Hi,

skype-probe is enable.

Now I'm testing a new rule for this user.

I'm allowing "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports).

Probably it will works but problem is that I want keep blocked "unknown-tcp" from any to any...

Do you know if PAN OS 5.0 will solve this problem? When will the new version?

Thanks

Regards

Hi Mauro,

If you still see Skype traffic being classified incorrectly I would suggest opening a support case so we can investigate.  We will likely need a client PCAP and the show session output showing the problem sessions but we should be able to add it to the application.

Thanks,

-- Kevin

Hi,

after I allowed "skype", "skype-probe", "unknown-tcp" and "unknown-udp" from "test-user" to any (any ports) everything works fine.

I see "unknow-tcp" traffic so problem is that some skype packets are not correctly recognized.

I will open a support case

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!