<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File blocking upload in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614428#M4853</link>
    <description>&lt;P&gt;Thanks Tom.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate it ..Cheers:)&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2024 15:17:48 GMT</pubDate>
    <dc:creator>zaidshaikh</dc:creator>
    <dc:date>2024-10-24T15:17:48Z</dc:date>
    <item>
      <title>File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614396#M4848</link>
      <description>&lt;P&gt;We have a requirement to Block uploads of file to Virustotal.com.&lt;/P&gt;
&lt;P&gt;We have SSL decryption working fine with URL filtering profiles applied.&lt;/P&gt;
&lt;P&gt;I created a new File blocking profile with application&amp;gt;&amp;gt; virustotal-base and virustotal web selected; File types&amp;gt;&amp;gt;All;&lt;/P&gt;
&lt;P&gt;Direction&amp;gt;&amp;gt;Upload; Action; Block&lt;/P&gt;
&lt;P&gt;Then i applied this profile to one internet facing machine having other profiles enabled as well, except Data filtering&amp;gt;None&lt;/P&gt;
&lt;P&gt;Now when i test on Virustotal website upload a text file, it is getting successfuly uploaded, also under Monitor&amp;gt;&amp;gt;Data filtering No logs are showing up.&lt;/P&gt;
&lt;P&gt;What am i missing pls guide....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 13:50:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614396#M4848</guid>
      <dc:creator>zaidshaikh</dc:creator>
      <dc:date>2024-10-24T13:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614410#M4849</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128470"&gt;@zaidshaikh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Great question!&amp;nbsp; The reason that PANW has separate App-IDs for file transfer protocols is so that they can be easily blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1729778943813.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63467i9B0921AE785B0632/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1729778943813.png" alt="TomYoung_0-1729778943813.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In your case, all you should need to do is create a security policy rule to block those 2 "uploading" applications and users should not be able to upload files to VirusTotal.&amp;nbsp; Since you are doing decryption, you can enable the application block page and users will get a web page stating the application is blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 14:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614410#M4849</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-10-24T14:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614424#M4851</link>
      <description>&lt;P&gt;Hi Tom&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the response.&lt;/P&gt;
&lt;P&gt;U mean the exisiting ALLOW policy having File blocking profile attached will not work? Since the same policy is performing decryption i thot it will get the visibility for the above two upload APP-IDs and will get block due the Action under the file blocking profile as Block.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i have to create a new security rule above the existing rule do i have to attach the file blocking profile or just select app-ids under application tab section. This i believe will not give me a Log under Data filtering.&lt;/P&gt;
&lt;P&gt;Apologies if i confuse u &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 15:04:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614424#M4851</guid>
      <dc:creator>zaidshaikh</dc:creator>
      <dc:date>2024-10-24T15:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614426#M4852</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128470"&gt;@zaidshaikh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your method can work, but is more complicated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you create a new rule blocking the applications, you do not need to attach a file blocking profile.&amp;nbsp; You are correct that the blocked files will not show up under Data Filter because the application, not the file, is blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No need to apologize!&amp;nbsp; All good questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 15:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614426#M4852</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-10-24T15:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614428#M4853</link>
      <description>&lt;P&gt;Thanks Tom.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate it ..Cheers:)&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 15:17:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/614428#M4853</guid>
      <dc:creator>zaidshaikh</dc:creator>
      <dc:date>2024-10-24T15:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/616153#M4953</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I did tried creating a rule with specific applications with Action Deny.&lt;/P&gt;&lt;P&gt;But it is not working, i tried upload a txt file and it is getting uploaded.&lt;/P&gt;&lt;P&gt;I opened a case with PA TAC, but not yet resolved asking to verify Decryption etc.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 16:22:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/616153#M4953</guid>
      <dc:creator>zaidshaikh</dc:creator>
      <dc:date>2024-11-05T16:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/1234031#M6092</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128470"&gt;@zaidshaikh&lt;/a&gt;&amp;nbsp;hope you are doing well. Any chance you can share a resolution from TAC? I'm having the same issue now with ChatGPT.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 11:58:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/1234031#M6092</guid>
      <dc:creator>EdmarFrancis</dc:creator>
      <dc:date>2025-07-15T11:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/1234151#M6095</link>
      <description>&lt;P&gt;Hi Edmar,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to resolve the issue with TAC assistance, wherein you need to having latest thread id installed.&lt;/P&gt;&lt;P&gt;Subsequently, you need to create to two rules, first rule with specific app-id in my case was virus-total-upload action deny.&lt;/P&gt;&lt;P&gt;Second rule will be web browsing ssl and virus-total-base action allow. likewise i am able to access the web url virus total, and at the same time upload any any file is getting blocked as well.&lt;/P&gt;&lt;P&gt;You can try the similar approach with gpt, taking one source machine as test and then once confident can be applied to all sources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps you.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 18:43:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/1234151#M6095</guid>
      <dc:creator>zaidshaikh</dc:creator>
      <dc:date>2025-07-16T18:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking upload</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/1234152#M6096</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315823"&gt;@EdmarFrancis&lt;/a&gt;&amp;nbsp;did you received my response, becoz i posted the reply, but it is not visible to me . let me know else i will re-post it&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 18:46:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/file-blocking-upload/m-p/1234152#M6096</guid>
      <dc:creator>zaidshaikh</dc:creator>
      <dc:date>2025-07-16T18:46:27Z</dc:date>
    </item>
  </channel>
</rss>

