Description

This article provides one behavior that SRX App ID junos:MICROSOFT-UPDATE may fail to identify the Microsoft Update HTTPs traffic under Content Delivery Network scenario.

Symptoms

When Microsoft Update application is hosted on a content delivery network (CDN), SRX AppSecure services(AppTrack, AppQoS, APBR and so on)may fail to identify the Microsoft Update HTTPs traffic when using with using App ID junos:MICROSOFT-UPDATE.

Solution

  • SRX Appid “junos:MICROSOFT-UPDATE” supports to do detection for both HTTPs and HTTP traffic.
    However when under CDN scenario, it mail fail to identify the Microsoft Update HTTPs traffic with using App ID junos:MICROSOFT-UPDATE.
  • When under CDN scenario and when HTTP GET request packet with host pattern like "xxx.windowsupdate.com", SRX will be able to identify MICROSOFT-UPDATE HTTP traffic. 

Modification History

2024-12-03 : Article Created