Skype-Probe sessions increase dramtically when blocking skype

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L0 Member

Skype-Probe sessions increase dramtically when blocking skype

Hi All,

Seem to be having a bit of a problem with skype-probe.

I have a PA-500 in Vwire mode behind a PIX FW, the customer wishes to block Skype traffic.

Observations:

1.     On the ACC the ammount of skype-probe traffic far exceedes any other traffic in terms of sessions

2.     The ammount of bytes of skype-probe traffic is roughly in relation to the amount of skype bytes

3.     When enabling a skype only block rule (still allowing skype-probe) the active session count sky rockets

The sessions that increase dramatically are from skype-probe these sessions go from a current 4,000 sessions to 50,000+ in a matter of under a minute until the skype block rule is disabled.

Any help and insight will be greatly appreciated

Cheers

Marc

attached is screen shots of skype-probe session count for last hour

Highlighted
Not applicable

Please reference the "Controlling Skype" document in knowledge point from the support.paloaltonetworks.com support portal. 

Highlighted
L3 Networker

My understanding is that you need to allow skype-probe traffic through to establish a connection, and then block the actual skype traffic once the Skype client believes it has connected. This prevents Skype from going evasive, but it does create a confusing situation on the client where it appears to be connected successfully, yet calling does not actually work.

Highlighted
L0 Member

skype-robe is allowed in a rule.

The rule set look like this:

Source Zone
Dest ZoneSourceDest
Source User
Application
Service
Action
TrustUntrustanyanyanyskypeanydeny
TrustUntrustanyanyKnown UsersVarious Apps (Incl skype-probe)anyallow

Before skype is disabled the session count for skype-proble is high, as soon as you deny skype on the PA the skype-probe sessions go through the roof, as said earlier from about 4k sessions to 40k sessions in seconds.

Highlighted
L7 Applicator

try setting the allow skype-probe rule before the block skype rule, this may help decrease the number of probe connections

Tom Piens - PANgurus.com
New to PAN-OS or getting ready to take the PCNSE? check out amazon.com/dp/1789956374
Highlighted
L0 Member

will give it a go and provide feedback once done.

Regards

Marc

Highlighted
L0 Member

Hi,

With a skype-probe allow rule above the skype block rule, we still experience the same volume of sessions

Marc

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!