- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-07-2013 12:16 AM
Hello Guys,
Have anyone of you noticed something regarding torrent(bittorrent, transmission..etc..)?
We received a report that a torrent app which is transmission is able to evade the app detection of Palo Alto NGFW.
I tested it in my lab, I use Bittorrent and I saw that it can really breach Palo Alto NGFW and successfully downloaded a file.
We traced the logs and sessions, we noticed that these torrent is using other app such as teredo, unknown-tcp, and unknown-udp.
I don't know if this has happened before but its new to me. We are expecting that if we block bittorrent, we dont have to block other apps, Isn't that how it should work?
Thank you.
Regards,
Hartkently
11-07-2013 08:27 AM
Hello Harkently,
What content version is your PAN firewall running on ?
Regards,
Kunal Adak
11-07-2013 04:39 PM
Hello Torrent,
If the application was not identified properly there are couple things which may have happened
> The application would have changed their signature which is not updated on PAN apps content yet
> There may be an issue in identifying the app because bittorent opens predict session and tries to map the child sessions as the traffic flows.
For any further clear analysis it would be nice to take flow basics and packet captures to understand what was the traffic and how the PAN analysed the apps to narrow down the issue.
Thanks
11-07-2013 08:52 PM
Hi Kunal,
currently the content version is 404-2015, I believed that is the latest update..
Thanks.
Regards,
Hartkently
11-07-2013 08:54 PM
Hi
If I'm not mistaken there hasn't been any update regarding bittorrent these past few weeks. I tried relaying this to PAN but what we did was just take the other app that bittorrent uses and put it on the block list. that way we are able to control bittorrent again.
thanks..
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!