Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Firewall_Head
Explorer

Abnormality in pattern matching of APP CONTRL BLADE

Hi Checkmates,

 

I have a security policy created for communication between a pair of device, I'm using a custom created TCP high port (TCP 30K+) in service and no applications are mentioned inside the rule. But when I'm checking the logs it is matched against an APP named net.TCP.

Can someone shed light on how this is happening, how is traffic matched against an APP which I never specified in the rule.

Thanks in advance!

 

======

WR,

FH

0 Kudos
40 Replies
the_rock
Legend
Legend

Can you check if app database is updates from smart console?

Andy

 

0 Kudos
Firewall_Head
Explorer

Looks good.

======

WR,

FH

0 Kudos
Firewall_Head
Explorer

It looks fine Andy.

====

WR,

FH

0 Kudos
the_rock
Legend
Legend

Send me direct message at noon EST (9.30 IST) and I can send you zoom.

Andy

0 Kudos
Firewall_Head
Explorer

Sure Andy, will do.

======

WR,

FH

0 Kudos
the_rock
Legend
Legend

Hey guys,

Tx for the remote. Just to update, below is what I mentioned about adding whatever services needed to customize the category services.

Btw, I will try test smart event shortly for automatic reaction.

Andy

the_rock
Legend
Legend

Hey bro,

For smart event automatic reaction, for the email alerts, see what I set up in the lab, will see if it actually works, I just used basic gmail, thats it.

Andy

Firewall_Head
Explorer

Hey Andy, @the_rock 

Hope you are doing well!

How were you able to pull off the configuration by using gmail?

Doesn't it need a password for authentication? (APP PASSWORD)

=====

WR,

FH @Chinmaya_Naik 

0 Kudos
the_rock
Legend
Legend

Hey man,

So sorry, was preoccupied with AV issue I have going on with a customer, so did not have chance to revisit this. Had to rebuild the smart event, so let me try it again and will update you either tomorrow or next week.

Andy

0 Kudos
Firewall_Head
Explorer

Thanks for the reply man.

We will discuss tomorrow then!

=====

WR,

FH

0 Kudos
the_rock
Legend
Legend

Lets check next week 🙂

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events