APP ID

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

APP ID

L0 Member

Hello Techie,

 

I've one generic query related to aap id feature, one of the PA docs says it requires 4packets or 2000bytes to identify any single applications where in live scenerio I do see see it works with only 1 single layer 7 packet(C2S/S2C) can identify the application though it was for dns traffic. Is it specific for UDP traffic.

 

Thanks

Gopal

1 REPLY 1

Cyber Elite
Cyber Elite

Hello,

As you have discovered, some applications are identified quicker. This is due to the standard structure of a DNS packet, in this case.

Regards,

  • 322 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!