<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Whatsapp File transfer Block in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/523621#M654</link>
    <description>&lt;P&gt;I know this thread seems to be a few months old, but I wanted to add that I had to do this exact thing this morning on one of our FWs and it worked fine.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whats-app chat and calls are still allowed.&lt;/P&gt;
&lt;P&gt;however, file transferring (even voice notes) is not.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rule I used looks like:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KarienVerster_0-1670506794649.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46006i0AFAAF8AAC9975F3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KarienVerster_0-1670506794649.png" alt="KarienVerster_0-1670506794649.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Basically, everything WhatsApp needs to work is allowed in this rule, except the 'whatsapp-file-transfer' application&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our &lt;STRONG&gt;catch-all-block-rule&lt;/STRONG&gt; at the end of our security policies will catch the file transfers, which is not explicitly allowed anywhere, and block them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We don't have any special decryption configured either. Palo Alto correctly classifies all this traffic so we could create this rule without issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using a PA460, on Firmware 10.2.3 if this helps.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230785"&gt;@Thomasevig&lt;/a&gt;&amp;nbsp;perhaps check your monitoring on the FW, while doing a file transfer on WhatsApp to see if your traffic is correctly classified.&amp;nbsp; If yes, then this rule should work for you.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tbh - I was trying to get only uploads on WhatsApp blocked, with downloads still working.&amp;nbsp; But I was unable to get this working.&amp;nbsp; It is either a block all file transfer or nothing it seems.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Dec 2022 14:48:36 GMT</pubDate>
    <dc:creator>KarienVerster</dc:creator>
    <dc:date>2022-12-08T14:48:36Z</dc:date>
    <item>
      <title>Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511826#M272</link>
      <description>&lt;P&gt;i work as a security specialist engineer at a moderate &lt;BR /&gt;enterprise.&lt;BR /&gt;recently my superiors have asked me to block whatsapp file transfer only(meaning chat would still work).&lt;BR /&gt;however i've tried anything using our Fw's but to no avail.&lt;/P&gt;
&lt;P&gt;from what i have read on some forums and various sources, i need to url block &lt;BR /&gt;mmi.whatsapp&lt;BR /&gt;mms and mmv..&lt;BR /&gt;i tried doing that yet it didn't seem to help. &lt;BR /&gt;i can still upload/download files from both &lt;BR /&gt;whatsapp web and the desktop application.&lt;/P&gt;
&lt;P&gt;is it possible to &lt;BR /&gt;get support from you on this matter please?&lt;BR /&gt;is blocking ft even achievable?&lt;/P&gt;
&lt;P&gt;thank you so much,&lt;/P&gt;
&lt;P&gt;best regards,&lt;/P&gt;
&lt;P&gt;Thomas.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 07:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511826#M272</guid>
      <dc:creator>Thomasevig</dc:creator>
      <dc:date>2022-08-15T07:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511842#M274</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;
&lt;P&gt;You would need to be blocking the Whatsapp file-sharing application, are you able to see this application on your firewall? To be able to you will need to be decrypting the Whatsapp traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 14:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511842#M274</guid>
      <dc:creator>MichaelWrigh</dc:creator>
      <dc:date>2022-08-15T14:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511977#M277</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;
&lt;P&gt;On the firewall, the application description says,&lt;BR /&gt;WhatsApp has integrated the TextSecure encryption protocol, which enforces certificate pinning to its most recent update. Due to this we can longer decrypt this application, and it will be added to the SSL exclude list. &lt;STRONG&gt;Policies enforcing "whatsapp-base" will continue to function normally, but policies using "whatsapp-file-transfer" can no longer be enforced&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ahandoo_0-1660639495559.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43164i63C2AB3F4D60C274/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ahandoo_0-1660639495559.png" alt="ahandoo_0-1660639495559.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately firewall cannot see what is sent by the client in an encrypted packet (chat/upload, etc). Furthermore, the application does not like to get decrypted as it uses end-to-end encryption. This means &lt;SPAN&gt;that even if we do SSL inspection we won’t be able to see the content of a message.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Although you can block the URLs to which the traffic is traversing provided we have the SNI information, however from my personal experience, these URLs keeps changing from time to time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 09:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511977#M277</guid>
      <dc:creator>ahandoo</dc:creator>
      <dc:date>2022-08-16T09:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511985#M278</link>
      <description>&lt;P&gt;Hi Michael,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unfortunately,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have already tried blocking both whatsapp file sharing and&lt;/P&gt;
&lt;P&gt;whatsapp-base applications on the&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fw yet that didn't seem to do anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 10:30:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511985#M278</guid>
      <dc:creator>Thomasevig</dc:creator>
      <dc:date>2022-08-16T10:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511986#M279</link>
      <description>&lt;P&gt;Hi Ahandoo,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i actually tried to block these applications, yet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to no avail.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also, can you please elaborate on the SNI Information?&lt;/P&gt;
&lt;P&gt;what exactly is it? and how do i obtain it?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 10:31:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511986#M279</guid>
      <dc:creator>Thomasevig</dc:creator>
      <dc:date>2022-08-16T10:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511994#M280</link>
      <description>&lt;P&gt;Hi Thomas,&lt;BR /&gt;&lt;BR /&gt;SNI is the Server Name Identification field present in the Client Hello of SSL/TLS Handshake. It allows the client to indicate the hostname which it is trying to connect. For more information , you can refer to this &lt;A href="https://knowledge.digicert.com/quovadis/ssl-certificates/ssl-general-topics/what-is-sni-server-name-indication.html" target="_self"&gt;link&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;You will have to take network trace or packet capture to know this information.&lt;BR /&gt;We can find multiple videos on youtube on how to find the SNI from a packet capture. You can check this &lt;A href="https://www.youtube.com/watch?v=gjrCI4GhQgI" target="_self"&gt;video&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 06:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/511994#M280</guid>
      <dc:creator>ahandoo</dc:creator>
      <dc:date>2022-08-18T06:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/512447#M290</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i still haven't managed to sort this issue out,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we're considering using a different solution&lt;/P&gt;
&lt;P&gt;as it appears to be un-solvable by the looks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;of it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you all for your contribution.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 11:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/512447#M290</guid>
      <dc:creator>Thomasevig</dc:creator>
      <dc:date>2022-08-21T11:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/512733#M296</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230785"&gt;@Thomasevig&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a lot of work associated with blocking/allowing URLs, not only for this but for a wide variety of scenarios. It can be tricky sometimes.&lt;BR /&gt;My lab experience using the URL Filtering profiles allowed me to block Whatsapp upload of images &amp;amp; videos while allowing the messages to be sent. I am sharing it if it can help.&lt;/P&gt;
&lt;P&gt;Created a URL Category including&amp;nbsp;&lt;BR /&gt;mmg.whatsapp.net/&lt;BR /&gt;*.cdn.whatsapp.net&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ahandoo_0-1661282359329.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43322iEFF7CD201DE953E6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ahandoo_0-1661282359329.png" alt="ahandoo_0-1661282359329.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Created a URL filtering profile and set the above created URL category to block.&lt;/P&gt;
&lt;P&gt;Added the URL filtering profile to the rule which matches the Whatsapp traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: In order to get the list of the URLs to block, I took a packet capture on the host which was running the Whatsapp application or the Whatsapp web.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Arnesh&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 19:29:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/512733#M296</guid>
      <dc:creator>ahandoo</dc:creator>
      <dc:date>2022-08-23T19:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/520012#M531</link>
      <description>&lt;P&gt;We are seeing the same behavior with our policy.&lt;/P&gt;
&lt;P&gt;It looks like at the moment Palo-Alto is unable to provide solution to block whatsapp file transfers.&lt;/P&gt;
&lt;P&gt;The method suggested above using URL categories also doesn't seem to work.&lt;/P&gt;
&lt;P&gt;If anyone have some other solution for this problem it would be very helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 16:31:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/520012#M531</guid>
      <dc:creator>Leonid.Rozgon</dc:creator>
      <dc:date>2022-11-02T16:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/522719#M631</link>
      <description>&lt;P&gt;hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there any other workaround we can implement?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;has anyone tried anything&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:23:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/522719#M631</guid>
      <dc:creator>Thomasevig</dc:creator>
      <dc:date>2022-11-29T09:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/523621#M654</link>
      <description>&lt;P&gt;I know this thread seems to be a few months old, but I wanted to add that I had to do this exact thing this morning on one of our FWs and it worked fine.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whats-app chat and calls are still allowed.&lt;/P&gt;
&lt;P&gt;however, file transferring (even voice notes) is not.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rule I used looks like:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KarienVerster_0-1670506794649.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46006i0AFAAF8AAC9975F3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KarienVerster_0-1670506794649.png" alt="KarienVerster_0-1670506794649.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Basically, everything WhatsApp needs to work is allowed in this rule, except the 'whatsapp-file-transfer' application&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our &lt;STRONG&gt;catch-all-block-rule&lt;/STRONG&gt; at the end of our security policies will catch the file transfers, which is not explicitly allowed anywhere, and block them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We don't have any special decryption configured either. Palo Alto correctly classifies all this traffic so we could create this rule without issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using a PA460, on Firmware 10.2.3 if this helps.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230785"&gt;@Thomasevig&lt;/a&gt;&amp;nbsp;perhaps check your monitoring on the FW, while doing a file transfer on WhatsApp to see if your traffic is correctly classified.&amp;nbsp; If yes, then this rule should work for you.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tbh - I was trying to get only uploads on WhatsApp blocked, with downloads still working.&amp;nbsp; But I was unable to get this working.&amp;nbsp; It is either a block all file transfer or nothing it seems.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 14:48:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/523621#M654</guid>
      <dc:creator>KarienVerster</dc:creator>
      <dc:date>2022-12-08T14:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp File transfer Block</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/529445#M839</link>
      <description>&lt;P&gt;You can test if enabling SSL decryption just for the destination FQDN/IP addresses of&amp;nbsp; WhatsApp out of working hours if it starts working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also there is an application debug that have described in the discussion below, so if you want to play again outside working hours you can try "Other use case that I know is to see the application shift if there is an issue how the Palo Alto changes the matched application by enabling the "appid" debug. "&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/td-p/402102" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/td-p/402102&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 10:40:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/whatsapp-file-transfer-block/m-p/529445#M839</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-02-01T10:40:18Z</dc:date>
    </item>
  </channel>
</rss>

