All application traffic gets blocked when we add unknown-tcp/udp application filter in Block rule

All application traffic gets blocked when we add unknown-tcp/udp application filter in Block rule

5572
Created On 04/25/23 05:35 AM - Last Modified 10/08/24 23:53 PM


Symptom


  • We have configured a security policy to block unknown-tcp and unknown-udp traffic using the application filter "unknown".image.png
  • Post upgrade from 9.1.x to 10.1.x, we were unable to access the internet, even if the application is being identified as "web-browsing" and the session end reason is "reset-both".
          image.png
  • When the application filter created for the unknown-tcp and unknown-udp are removed from the block policy, then we were able to access the internet.
 


Environment


  • Firewall
  • PAN-OS Version: 10.1.x, 10.2.x


Cause


  • In the session info you could observe that the application as "web-browsing" and hitting the "block" policy.
    image.png
    
    
  • When we add the name "unknown" as an application filter it matches a decoder name "unknown".
  • This will cause incorrect policy matching when a decoder name is used as an application filter name.

 

 



Resolution


Target fix version PAN-OS 11.1.0
  1. Avoid using application filters, custom apps, and application groups that match the decoder names.
  2. We can avoid this by prepending, inserting, or appending their application filter, application group, and custom app names with "one or two underscores (_ or __)" as the decoder names rarely contain an underscore.
  3. Here in this scenario, the "unknown" is the name of the decoder present in the firewall.
  4. Before changes are made to the application filter:
admin@Lab81-233-PA-VM# show application-filter unknown
unknown {
  category unknown;
}
Post changes made to the application filter:
admin@Lab81-233-PA-VM# show application-filter unknown-category
unknown {
  category unknown;
}


Additional Information


  • Create a Security Policy Rule

    https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/security-policy/create-a-security-policy-rule

 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kHkECAU&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language