URL category for anydesk

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

URL category for anydesk

L3 Networker

Hi community!

 

I´m trying to create a url custom category that matches Anydesk traffic so I can decide what non-decrypt rule anydesk is using.

In the URL filtering logs I only see the url anynet%20relay:6568 and I tried to create a custom category with that url but it doesn´t seem to match. 

 

I have followed also the suggestions from this discussion without success:

https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anyd...

 

It seems there´s a limitation with the token separators that Palo Alto offers:(. / ? & = ; +) and you cannot create an expression to match urls like anynet%20relay:6568.

 

Does anyone has a suggestion on how to create an expression that can match urls like anynet%20relay:6568??

 

Many thanks in advance!

2 REPLIES 2

Cyber Elite
Cyber Elite

%20 is a blank space which doesn't make sense in a URL

 

according to anydesk you'd need to use *.net.anydesk.com as FQDN and ports tcp/80, tcp/443 and tcp/6568, and udp/5000150003 for discovery

 

https://support.anydesk.com/knowledge/firewall 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Cyber Elite
Cyber Elite

Anydesk does use spaces and %20 in URL so add also those:

 

*.net.anydesk.com/

AnyNet Relay

anynet%20relay:80/

anynet%20relay/

 

Raido_Rattameister_1-1747228162624.png

 

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 452 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!