Whatsapp traffic cannot recognize in PA for iPhone user.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Whatsapp traffic cannot recognize in PA for iPhone user.

L2 Linker

Recently iPhone users only facing in WhatsApp "connecting" message, User could not send a message and make a call 

on corporate wireless network But, working in mobile network.
It was working before, day by day users facing this issue is increasing. Still WhatsApp working for some of the iPhone users on same wireless network. 

Tried IOS software update and WhatsApp update as well but no luck.

Same is working for all andriod users even on old version of WhatsApp.

 

in firewall end, WhatsApp traffic is cannot recognized as whatsapp-base for iphone. it shows as unknown-tcp.

No recent changes in our firewall end.

 

 

 

Thanks,
Sharthu
49 REPLIES 49

L2 Linker

An App-ID update fixing this issue should be delivered 3rd week of september. No other solution than the workaround explain in this thread.

Cyber Elite
Cyber Elite

Workaround is to permit unknown-tcp traffic on port 443 and 5222 to WhatsApp IP ranges.

You can get WhatsApp IP ranges from https://developers.facebook.com/docs/whatsapp/guides/network-requirements/

 

Look for "WhatsApp server IP addresses and ranges (.zip file)" on the page.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

hi , Did you get any response? 

Like I said, the only answer is : "wait for th App-ID update 3rd week of september". Before this you have the workaround described in this thread.

L1 Bithead

Hi guys! I saw that an App-ID update was released (Version 8756), but in my case the problem continues. Anyone else still having the same problem?

 

Applications Content Release Notes:
https://proditpdownloads.paloaltonetworks.com/content/app-8756-8298.html?__token__=exp=1695974588~ac...

Error message on release note :

 

An error occurred while processing your request.

Reference #199.8e327b68.1695384246.3cd9a3ba

 

How can you know this App-ID update should fix the problem?

Sorry. Follow the updated link. In "Modified Applications" it shows subscription updates for WhatsApp and Telegram.

 

https://proditpdownloads.paloaltonetworks.com/content/app-8756-8298.html?__token__=exp=1695974588~ac... 

L2 Linker

After content update 8756 I see no difference whatsoever. Lots of Whatsapp-traffic is still being classified as tcp-unknown an subsequently gets dropped.

L1 Bithead

If someone has been able to solve this problem, please comment the solution for the community. Thanks

I get an answer from Palo Alto support to try with update 8756-8298 (09/20/23) or higher.

After that everything works correctly (Whatsapp and Instagram) with no unknown-tcp or unknown-udp anymore.


@MarketMaker wrote:

I get an answer from Palo Alto support to try with update 8756-8298 (09/20/23) or higher.

After that everything works correctly (Whatsapp and Instagram) with no unknown-tcp or unknown-udp anymore.


That is exactly the update I tested (and I assume Antonio-Siqueira did so too). In my case that does not help to solve the problem. At this moment we run Content Update 8760, but as far as I can make out from the Release Notes there haven't been any changes to Whatsapp since update 8756.

Did update 8756 (or later) solve this issue for you, MarketMaker?

Yes it does. and whatsapp works well without any unknown-tcp app rules

 

MarketMaker_0-1696348165953.png

 

L1 Bithead

There will be a new update on October 17th, according to the release note for version 8762. Follow the link...

 

https://proditpdownloads.paloaltonetworks.com/content/app-8762-8327.html?__token__=exp=1697443449~ac... 

 

Please let us know if received any updates from TAC

L2 Linker

Just a quick note to let you know that TAC is still working on this issue. They studied logs and captures from our firewall but may possibly need some more logging and captures. So still work in progress. Lets hope they find something helpfull.

  • 11689 Views
  • 49 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!