<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 6.1 Application Detector - Not detecting certain connections in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-6-1-application-detector-not-detecting-certain-connections/m-p/3897451#M1029354</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am facing the same exact issue with application detector and i am running version 6.2.3.13.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you solved the problem or found a solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;George&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2019 10:08:35 GMT</pubDate>
    <dc:creator>gaboughanem</dc:creator>
    <dc:date>2019-07-25T10:08:35Z</dc:date>
    <item>
      <title>FTD 6.1 Application Detector - Not detecting certain connections</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-1-application-detector-not-detecting-certain-connections/m-p/2964845#M1029353</link>
      <description>&lt;P&gt;Anyone run into issues with FTD, in what appears to be random cases the application detection engine doesn't classify a flow with AVC application protocol / client information?&lt;/P&gt;
&lt;P&gt;I have seen it on SYSLOG, NTP, NetBIOS-ssn (SMB [TCP 445]), and other applications. &amp;nbsp;It is not consistent, meaning NTP will be classified correctly for quite a while and then randomly a session will not be. &amp;nbsp;When it is not, there is no Application protocol / client / web application listed in the log entry for that connection.&lt;/P&gt;
&lt;P&gt;This is a major issue as I am attempting to use AVC rules, and when the application detection doesn't work correctly the traffic hits the default action policy which is set to deny / block.&lt;/P&gt;
&lt;P&gt;TAC suggested changing all the allow rules to log at the end of the connection. &amp;nbsp;They suggested that would provide more accurate logging when the initial packets of an application are not classified at that point. &amp;nbsp;That didn't have a impact and I currently running with a policy that includes temporary port / services rules.&lt;/P&gt;
&lt;P&gt;Ralph&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:55:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-1-application-detector-not-detecting-certain-connections/m-p/2964845#M1029353</guid>
      <dc:creator>Ralph Rye</dc:creator>
      <dc:date>2020-02-21T13:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.1 Application Detector - Not detecting certain connections</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-1-application-detector-not-detecting-certain-connections/m-p/3897451#M1029354</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am facing the same exact issue with application detector and i am running version 6.2.3.13.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you solved the problem or found a solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;George&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 10:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-1-application-detector-not-detecting-certain-connections/m-p/3897451#M1029354</guid>
      <dc:creator>gaboughanem</dc:creator>
      <dc:date>2019-07-25T10:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.1 Application Detector - Not detecting certain connections</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-1-application-detector-not-detecting-certain-connections/m-p/3897452#M1029355</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am facing the same exact issue with application detector and i am running version 6.2.3.13.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you solved the problem or found a solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please anyone can assist?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;George&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 10:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-1-application-detector-not-detecting-certain-connections/m-p/3897452#M1029355</guid>
      <dc:creator>gaboughanem</dc:creator>
      <dc:date>2019-07-25T10:09:40Z</dc:date>
    </item>
  </channel>
</rss>

