This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

iDevices Switch (smart home device) being classified as Torrent Clients P2P by Application Filter

I have a couple iDevice Switches in my home that are utilizing a firewall rule I created for my IOT devices that has a customized Application Filter. One thing I noticed is the iDevice Switches are causing the Sophos XG Application Filter to block an application classified as 'Torrent Clients P2P'. Here is the firewall log:

2018-05-30 03:06:20Application Filtermessageid="17051" log_type="Content Filtering" log_component="Application" log_subtype="Denied" fw_rule_id="7" user="" user_group="" appfilter_policy_id="9" category="P2P" app_name="Torrent Clients P2P" app_risk="5" app_technology="P2P" app_category="P2P" src_ip="165.254.21.196" src_country="USA" dst_ip="[iDevice Switch]" dst_country="R1" protocol="UDP" src_port="30041" dst_port="60752" bytes_sent="0" bytes_received="0" status="Deny" message="" appresolvedby="Signature"

I contacted the iDevice company and they confirmed the source IP address is legitimate and coming from their servers. Apparently what's causing this is the 'iDevices Remote Access' feature which allows you to access your iDevice devices from the iDevice app outside of your local home network. I'm posting this data here incase anyone else runs into the same issue in the future and hoping the Sophos team can use this data to update their application signature database. If there's any other data you need, please let me know!

Additionally, this is not published anywhere but the iDevice networking team provided me with the ports their devices utilize which is UDP 29979:30170.



This thread was automatically locked due to age.
  • Noticed another block of 'Torrent Clients P2P' in my logs but this time it was from my Ring Pro Doorbell. Here is the firewall log:

    2018-08-22 14:10:51Application Filtermessageid="17051" log_type="Content Filtering" log_component="Application" log_subtype="Denied" fw_rule_id="2" user="" user_group="" appfilter_policy_id="9" category="P2P" app_name="Torrent Clients P2P" app_risk="5" app_technology="P2P" app_category="P2P" src_ip="172.16.16.17" src_country="R1" dst_ip="13.52.2.194" dst_country="USA" protocol="UDP" src_port="15063" dst_port="15063" bytes_sent="0" bytes_received="0" status="Deny" message="" appresolvedby="Signature"

    The UDP protocol and port 15063 are used by Ring to communicate with their servers and the destination IP is going to Ring's servers, so this is legitimate traffic.

     

    Here's another one as well coming from an iPhone but I'm not sure what app is causing it:

    2018-08-11 22:00:04Application Filtermessageid="17051" log_type="Content Filtering" log_component="Application" log_subtype="Denied" fw_rule_id="5" user="" user_group="" appfilter_policy_id="10" category="P2P" app_name="Torrent Clients P2P" app_risk="5" app_technology="P2P" app_category="P2P" src_ip="172.16.16.24" src_country="R1" dst_ip="17.249.41.247" dst_country="USA" protocol="TCP" src_port="50146" dst_port="5228" bytes_sent="0" bytes_received="0" status="Deny" message="" appresolvedby="Signature"