How to mitigate an increase in unknown-tcp or unknown-udp traffic
17683
Created On 01/11/24 21:16 PM - Last Modified 01/11/24 23:53 PM
Objective
- To mitigate an abnormal increase in traffic with application unknown-tcp or unknown-udp seen in the traffic logs.
Environment
- Next Generation Firewall
- unknown-tcp
- unknow-udp
Procedure
- Inspect the firewall system logs: MONITOR> Logs> Traffic and use the ( app eq 'unknown-tcp' ) or (app eq 'unknown-udp') search filter. Define the traffic whose application has not been identified by the firewall (Determine its Source Zone, Source IP address, Destination Zone, Destination IP address, Destination port, etc...).
- If the application of the defined traffic was previously properly identified by the firewall then suddenly stopped being recognized:
- Check if the content or application version is up-to-date on your firewall: DEVICE> Dynamic Updates then:
- Application and Threats (for firewalls with valid Threat Prevention license installed)
- Application (for firewalls with no Threat Prevention license).
- If needing to update the content or application version refer to install content updates.
- Report a misidentification of an application.
- Check if the content or application version is up-to-date on your firewall: DEVICE> Dynamic Updates then:
- If the application of the defined traffic was never recognized by the firewall then depending on the used case:
- Create a customer application for that traffic refer to Pro-Tips: Unknown Applications and how to create a an application override for this traffic.
- Request a new app-id from Palo Alto Networks for his traffic.