Torrent

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Torrent

L2 Linker

Hello Guys,

Have anyone of you noticed something regarding torrent(bittorrent, transmission..etc..)?

We received a report that a torrent app which is transmission is able to evade the app detection of Palo Alto NGFW.

I tested it in my lab, I use Bittorrent and I saw that it can really breach Palo Alto NGFW and successfully downloaded a file.

We traced the logs and sessions, we noticed that these torrent is using other app such as teredo, unknown-tcp, and unknown-udp.

I don't know if this has happened before but its new to me. We are expecting that if we block bittorrent, we dont have to block other apps, Isn't that how it should work?

Thank you.

Regards,

Hartkently

4 REPLIES 4

L5 Sessionator

Hello Harkently,

What content version is your PAN firewall running on ?

Regards,

Kunal Adak

L4 Transporter

Hello Torrent,

If the application was not identified properly there are couple things which may have happened

> The application would have changed their signature which is not updated on PAN apps content yet

> There may be an issue in identifying the app because bittorent opens predict session and tries to map the child sessions as the traffic flows.

For any further clear analysis it would be nice to take flow basics and packet captures to understand what was the traffic and how the PAN analysed the apps to narrow down the issue.

Thanks

Hi Kunal,

currently the content version is 404-2015, I believed that is the latest update..

Thanks.

Regards,

Hartkently

Hi

If I'm not mistaken there hasn't been any update regarding bittorrent these past few weeks. I tried relaying this to PAN but what we did was just take the other app that bittorrent uses and put it on the block list. that way we are able to control bittorrent again.

thanks..

  • 4901 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!