Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 

Tip of the Week - Application Control Best Practices

This widget could not be displayed.
2 Comments
Vladimir
Champion
Champion

Valeri Loukine‌,

Can we get a definitive answer on where "Any Recognized" is now?

It is explicitly mentioned in this current SK:

Setting Your Policy for Unknown Traffic

"Unknown traffic" is non-HTTP traffic that does not match anything in your current application database. Logs for unknown traffic should be examined carefully to understand what is behind them. Traffic that results in such a log could be a product of a protocol that is not yet supported, anonymized traffic which uses a proprietary protocol, or even a mis-detected supported protocol or application.

As the options listed have either security or connectivity concerns (often both), report any missing protocol or misdetection directly to the Application Control team. In general, once the unknown traffic has been inspected and categorized correctly, it is recommended you block such traffic facing the Internet and continue to monitor internal traffic.

Note: Unknown traffic will be matched on rules containing "Any Recognized" in addition to specific rules.

But it is not available in R80.10 and R80.20 and I am not sure about future releases.

Additionally, the Note above does not seem to make sense. It is either "Unknown" or "Recognized".

Thank you,

Vladimir

_Val_
Admin
Admin

Let me look into that