- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-24-2014 07:06 AM
Hello,
I have created below policy as per the policy
twitter is not working; however twitter application is allowed.
Is there any way to troubleshoot twitter application for above mentioned security policy?
Best Regards,
05-24-2014 09:37 AM
Hello Parvez,
The Policy configuration is looking fine. The only, possibility which might block "twitter" traffic through the PAN firewall, if App-ID is unable to identify the traffic correctly and twitter traffic is identified as "Unknown-TCP". I had a similar issue, where "twitter" traffic was unable to catch by App-ID ( Application Identification).
Hence, could you please create a test policy for one test machine and allow Unknown-TCP and let us know the result.
Thanks
05-24-2014 11:28 AM
Hello Parvez,
Could you please let me know, what "Application-Threat" version is running on your firewall. In my test box, i have 437-2224 installed and twitter is working just fine. If your PAN is not running into the latest one, could you please install the latest one and check.
FYI:
Thanks
05-25-2014 06:22 PM
You may try to do a NSLOOKUP on one of the testing PC, see what is the Twitter server IP address that it is trying to access.
After that, in the GUI --> Traffic log, you may use filter like ( addr.src in IP_ADD_OF_THE_TESTING_PC ) and ( addr.dst in IP_ADD_OF_THE_TWITTER_SERVER ) to check the security policy that the traffic hitting.
Also you can check the real time session in the CLI by using 'show session all filter source IP_ADD_OF_THE_TESTING_PC destination IP_ADD_OF_THE_TWITTER_SERVER'.
05-25-2014 11:01 PM
Hello Parvez,
There are many possible reasons, which could cause this issue. As mzh said, you could check the real time session in the CLI by using 'show session all filter source IP_ADD_OF_THE_TESTING_PC destination IP_ADD_OF_THE_TWITTER_SERVER'. Also, grab the session ID from there and apply a CLI command PAN> show session id XYZ >>>>>>>> to get detailed information about that session, i.e NAT rule, security rule, ingress/egress interface etc.
Thanks
05-26-2014 06:17 AM
Thanks HULK, After downloading the latest version of "Applications and Threats" resolved the issue.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!