- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-21-2012 05:00 AM
Hello,
Since I have updated my active/passive cluster with latest Application and threat content (version 339, released yesterday), some ssl traffic is now recognized as "tor" application.
This traffic is only ssl, not tor.
Is someone else have this problem ??
I have 2 PA-4020 version 4.1.9.
I open a case for this with my network integrator.
I returned to the version 338, it solve the problem.
Regards,
Franck.
11-22-2012 01:23 AM
Version 340 was released a few hours ago:
"
Note: This content release fixes an issue in content version 339 where some SSL traffic was being misidentified as tor.
"
11-21-2012 05:50 AM
Hi,
we have the same problem..
Hochschule Magdeburg
PA-4050, 4.1.8
Regards,
Manfred
11-21-2012 06:50 AM
Same here, PA-5050 cluster, 4.1.9
11-21-2012 10:02 AM
Same problem here, rolling back to 338. Anyone open a case on this with PA yet?
11-21-2012 10:03 AM
Same issue here.. Rolled back to 338.. just opened a case with PA.
11-21-2012 10:12 AM
Thanks - rolling back to 338 here as well, figured no point us all opening the same so long as you tell them it's not just an isolated case.
11-21-2012 10:15 AM
Yep.. they're aware. Already got an email back from our SE saying it's a false positive and we should be seeing a re-release with a fix shortly.
11-21-2012 10:24 AM
Great - thanks for the update.
11-21-2012 12:04 PM
Hi Guys,
For what we have learned so far through cases are that the following apps are being mis-classified as Tor:
Cisco vpn
Imap
Roku
Radius
Citrix apps
Please revert back to last content version. We are in the process of pulling the content version from the update server until we fix this problem.
Thanks,
Syed Hasnain
11-21-2012 12:21 PM
Are you missing SSL from that list?
11-21-2012 12:26 PM
Yes,
SSL should be in the list too.
Thanks,
Syed Hasnain
11-22-2012 01:23 AM
Version 340 was released a few hours ago:
"
Note: This content release fixes an issue in content version 339 where some SSL traffic was being misidentified as tor.
"
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!