JohnP, I have run into the same issue as you have and have the same reservations with allowing unknown-tcp just to let someone use skype. This seems like a bigger security risk as there is bound to be quite a few 'unknown-tcp' apps that I don't want allowed by this rule. This could stem from my misunderstanding of exactly what unknown-tcp really is. Right now I have Skype and skype-probe allowed without any issues to the user, but I still get the dependency warning for unknown-tcp for each commit. Palo Alto, Is it possible to get rid of the dependency error if skype is working? What exactly does unknown-tcp allow besides a port scan for skype? Thanks, CMAGGAR
... View more