<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: zenmate application in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179207#M212</link>
    <description>&lt;P&gt;If I recall correctly, you will need to use the decryption port mirror feature and stream the packets to a connected device. There you should be able to view decrypted traffic using a tool such as tcpdump or wireshark.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;decryption port mirror feature and stream the packets to a connected device. - can let me know how exactly to do this ... this is VM FW in my lAB&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Sep 2017 17:30:02 GMT</pubDate>
    <dc:creator>Rameshwar</dc:creator>
    <dc:date>2017-09-28T17:30:02Z</dc:date>
    <item>
      <title>zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/176575#M201</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;zenmate application is available in PA app but it is not blocking the traffic ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;tried using the URL based but pcap doesnt show any URL&lt;/P&gt;&lt;P&gt;tried to block through client hello SNI but no lcuk ....&lt;/P&gt;&lt;P&gt;please advise how i can block this on PA&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;app name - zenmate - browser based proxy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 16:35:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/176575#M201</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2017-09-14T16:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/176589#M202</link>
      <description>&lt;P&gt;If a known App-ID is not working as expected you should definitely open a support case to troubleshoot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Given that this is an encrypted, evasive VPN/proxy app I'm not sure how effective a custom signature would be.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 17:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/176589#M202</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2017-09-14T17:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/177257#M203</link>
      <description>&lt;P&gt;I"m not sure, but it sounds like you might be applying the app-id rule for encrypted traffic without setting up the decryption rule. &amp;nbsp;In order to apply inspected polcies on ssl traffic you will need to decrypt the the traffic first. &amp;nbsp;As you noted things like the url are not visible in the encrypted&amp;nbsp;stream.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/create-a-decryption-policy-rule.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/create-a-decryption-policy-rule.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 10:13:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/177257#M203</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-09-18T10:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/178983#M209</link>
      <description>&lt;P&gt;hi , i have the decryption in place .. but when i do a pcap it doesnt show any url ., is there any way to create a custom app to block zenmate ?wihout url&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 16:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/178983#M209</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2017-09-27T16:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179153#M210</link>
      <description>&lt;P&gt;Pretty sure the pcaps are not the decrypted internal view that is why you can't see the URL.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To use the built in app-id (best option) you need to use the app-id on a decryption rule so that the stream can be fully seen to match the PA patterns. &amp;nbsp;Make sure the decryption is working and that the traffic from the clients to this application are hitting that rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can enable decryption and setup a url blacklist. &amp;nbsp;And the same deal basically applies. &amp;nbsp;Decryption must be working and the rule has to be hit by the traffic. &amp;nbsp;But since there is an app-id for this you should work on the first option.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 11:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179153#M210</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-09-28T11:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179203#M211</link>
      <description>&lt;P&gt;If I recall correctly, you will need to use the decryption port mirror feature and stream the packets to a connected device. There you should be able to view decrypted traffic using a tool such as tcpdump or wireshark.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 16:38:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179203#M211</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2017-09-28T16:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179207#M212</link>
      <description>&lt;P&gt;If I recall correctly, you will need to use the decryption port mirror feature and stream the packets to a connected device. There you should be able to view decrypted traffic using a tool such as tcpdump or wireshark.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;decryption port mirror feature and stream the packets to a connected device. - can let me know how exactly to do this ... this is VM FW in my lAB&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 17:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179207#M212</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2017-09-28T17:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179208#M213</link>
      <description>&lt;P&gt;&lt;SPAN&gt;o use the built in app-id (best option) you need to use the app-id on a decryption rule so that the stream can be fully seen to match the PA patterns. &amp;nbsp;Make sure the decryption is working and that the traffic from the clients to this application are hitting that rule.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;you need to use the app-id on a decryption rule - can you please let me know how can i get this work&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 17:34:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179208#M213</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2017-09-28T17:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179356#M214</link>
      <description>&lt;P&gt;These are the rule instructions.&amp;nbsp; In step 3 you will need to include the app-id for zenmate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the rules must be ordered so that this rule is hit before any other rule that the zenmate traffic may match.&amp;nbsp; The policies are processed in order top to bottom and as soon as the traffic is matched we stop looking at further rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enable logging so that you can verfiy what traffic is matching which rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/create-a-decryption-policy-rule.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/create-a-decryption-policy-rule.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2017 09:38:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179356#M214</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-09-29T09:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179504#M215</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the information ,but i have already done the steps and it is not detecting the application&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2017 16:08:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179504#M215</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2017-10-01T16:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: zenmate application</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179505#M216</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it seems i found out the work around for this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;chrome extension zenmate - once the website which is blocked on the FW can be accessible if the ssl decryption is not enabled after connecting the zenmate. after the zenmate is connected and if the ssl decrypt is not enabled the blocked website will work , once you enable the ssl decrypt i.e ssl forward proxy it will start blocking the traffic as before so in this case connecting to zenmate chrome extension is of no use&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;zenmate application - zenmate installed app on local system behaviour is different as extension , ssl decrypt cannot block this . zenmate app is using IKE application to connect to the proxy server , we have to block the IKE application in the security policy and it will not allow the connection to be successful , but we have to keep in mind that IKE is been used for ipsec so if you have ipsec vpn then it can block the legitimate traffic . so in this case you can select the zone from may be trust to untrust i,e direct internet and apply the policy so it will only block the traffic which is gloing to untrust and not to the ipsec tunnel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2017 17:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/zenmate-application/m-p/179505#M216</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2017-10-01T17:14:32Z</dc:date>
    </item>
  </channel>
</rss>

