An engineer has been tasked with reviewing traffic logs to find applications the firewall is unable to identify with App-ID. Why would the application field display as incomplete?
A.
There is insufficient application data after the TCP connection was established.
B.
The TCP connection was terminated without identifying any application data.
C.
The TCP connection did not fully establish.
D.
The client sent a TCP segment with the PUSH flag set.
Incomplete --> App-ID labels traffic as incomplete when either the three-way TCP handshake does not complete or when the handshake completes but no data follows the handshake. Traffic labeled as incomplete by App-ID is not really an application.
1-3 packets exchanged ---> incomplete, because not even TCP handshake was completed
4-10 packets exchanged ---> insufficient data, because TCP was completed but we did not see enough packets to precisely determine what application is it
11-more packets exchanged ---> if we can't determine what is the app, it is marked as "unknown"
As per EDU-210: Classifying (Labeling) TCP Traffic
incomplete: Three-way handshake did not complete or was followed by no data
For A, the label will be "insufficient-data"
Ignore the comment before, C is correct.
Incomplete in the application field:
Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application.
One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
I believe A is correct. The key here is that the admin is reviewing traffic logs, if tcp handshake didnt complete then with default log settings it would not be recorded in the traffic log. The insufficient-data means that tcp session was established and logged after session ended but there wasnt enough data for the firewall to establish the application type.
"Incomplete" means that "either the three-way TCP handshake did not complete" or "the three-way TCP handshake **did** complete
but there was no data after the handshake to identify the application."
No data is the key.
C is correct as per URL https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
Incomplete in the application field:
Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application.
One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.
It could be A or C
"Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was not enough data after the handshake to identify the application. In other words that traffic being seen is not really an application."
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
That being said there's also 'insufficient data' where there's not enough data after the three way handshake so incomplete is probably 'best' as did not fully establish so I think C.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
SCCUser
1 day, 9 hours agoCro13
4 months agoATRRHMN
6 months, 1 week agoMarshpillowz
11 months, 2 weeks agoJRKhan
1 year agoJRKhan
1 year agodgonz
1 year, 4 months agojhenao89
1 year, 1 month agosov4
1 year, 5 months agoSpippolo
1 year, 11 months agooelsayed
1 year, 12 months agoLexus1323
2 years agoconfusion
2 years, 2 months agoAlen
2 years, 2 months agobimyo
2 years, 3 months agomysteryzjoker
2 years, 3 months agomysteryzjoker
2 years, 2 months agosecdaddy
2 years, 3 months agosecdaddy
2 years, 3 months agoGabuu
2 years, 3 months ago