<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pokemon GO in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/97217#M111</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my research you can block the domain&amp;nbsp;&lt;STRONG&gt;pgorelease.nianticlabs.com &lt;/STRONG&gt;and the clients will not be able to reach out to the server to play the game. This does not however stop the employee from using their mobile data plan to continue playing the game.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Tyler&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2016 12:39:47 GMT</pubDate>
    <dc:creator>tboire</dc:creator>
    <dc:date>2016-07-13T12:39:47Z</dc:date>
    <item>
      <title>Pokemon GO</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/96642#M109</link>
      <description>&lt;P&gt;With the rise in popularity of the new Pokemon GO app, has anyone had the opportunity to build a signature or possibly even gather a pcap of the traffic that could be shared (the site is not allowing signups right now so I am unable to produce my own test traffic to collect).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have received complaints from as high as our CIO, that too many people are walking around playing this game and we need to report on it and block is ASAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated,&lt;/P&gt;&lt;P&gt;-adam&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 04:04:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/96642#M109</guid>
      <dc:creator>aelmore</dc:creator>
      <dc:date>2016-07-12T04:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Pokemon GO</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/97083#M110</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't seen the game's traffic since it hasn't been released yet in Canada, but the developer's previous game called Ingress relies heavily on Google API. You might have a hard time identifying the application without decrypting the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 03:50:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/97083#M110</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-07-13T03:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Pokemon GO</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/97217#M111</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my research you can block the domain&amp;nbsp;&lt;STRONG&gt;pgorelease.nianticlabs.com &lt;/STRONG&gt;and the clients will not be able to reach out to the server to play the game. This does not however stop the employee from using their mobile data plan to continue playing the game.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Tyler&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 12:39:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/97217#M111</guid>
      <dc:creator>tboire</dc:creator>
      <dc:date>2016-07-13T12:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Pokemon GO</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/97251#M112</link>
      <description>&lt;P&gt;Thanks for all the feedback. I can confirm that I also see the app attempting to use the following URLs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pgorelease.nianticlabs.com&lt;BR /&gt;&amp;nbsp; &amp;nbsp;- &amp;nbsp; Using a *.nianticlabs.com certificate&lt;BR /&gt;appload.ingest.crittercism.com&lt;BR /&gt;&amp;nbsp; &amp;nbsp;- &amp;nbsp; Using a *.ingest.critterciscm.com certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The latter URL appears to be a third party app analytics company. I've yet to receive an executive order to authorize blocking, but I believe tboire is likely correct that blocking the Niantic URL will prevent connections. Should I get approval to block, that is my next course of action.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks everyone.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 13:31:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/97251#M112</guid>
      <dc:creator>aelmore</dc:creator>
      <dc:date>2016-07-13T13:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Pokemon GO</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/161872#M179</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33861"&gt;@aelmore&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44300"&gt;@tboire&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31211"&gt;@BenjAudy.MTL&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I know I am late in this thread, but I wanted to share this two options with you all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Option 1: URL filtering&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Simply blacklist the following url: &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;pgorelease.nianticlabs.com&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;(this is used to make API calls by the APP)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Option 2: Create a custom application which looks for the SNI string&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;set application pokemon-go default port tcp/443&lt;/P&gt;&lt;P&gt;set application pokemon-go signature PG-SSL and-condition "And Condition 1" or-condition "Or Condition 1" operator pattern-match pattern pgorelease.nianticlabs.com&lt;/P&gt;&lt;P&gt;set application pokemon-go signature PG-SSL and-condition "And Condition 1" or-condition "Or Condition 1" operator pattern-match context ssl-req-client-hello&lt;/P&gt;&lt;P&gt;set application pokemon-go signature PG-SSL scope protocol-data-unit&lt;/P&gt;&lt;P&gt;set application pokemon-go signature PG-SSL order-free no&lt;/P&gt;&lt;P&gt;set application pokemon-go signature PG-SSL comment “Pattern match against the SNI for Pokemon Go"&lt;/P&gt;&lt;P&gt;set application pokemon-go category media&lt;/P&gt;&lt;P&gt;set application pokemon-go subcategory gaming&lt;/P&gt;&lt;P&gt;set application pokemon-go technology client-server&lt;/P&gt;&lt;P&gt;set application pokemon-go description "Pokemon Go is a social game released in 2016 by Niantic Labs."&lt;/P&gt;&lt;P&gt;set application pokemon-go risk 1&lt;/P&gt;&lt;P&gt;set application pokemon-go parent-app ssl&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 04:44:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/pokemon-go/m-p/161872#M179</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-19T04:44:58Z</dc:date>
    </item>
  </channel>
</rss>

