<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTP partial response - Security protection bypass in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/http-partial-response-security-protection-bypass/m-p/1260011#M7040</link>
    <description>&lt;P&gt;The Palo Firewall supports HTTP partial response and is enabled by default, best practice is to disable HTTP partial response but this is a global setting.&amp;nbsp; Doing so will break access to numerous internet based systems like youtube, and a number of other systems that utilise chuck encoding, including palo's own content updates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When&amp;nbsp;HTTP partial response is allowed, and&lt;SPAN&gt;&amp;nbsp;a download is blocked due to file blocking policy, AV signature etc, and it is hosted on a site that supports resumption (which is very common these days), a user can simply select resume and the file will be downloaded, even more of an issue is lately I have seen browsers automatically resume downloads, and a number of other solutions will automatically resume a failed download&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What is even worse is that the firewall logs will record the file was blocked, but not that the file was then successfully downloaded, so the logs are incorrect.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A feature request exists to either fix or enhance the ability to selectively block / allow&amp;nbsp;HTTP partial response based on rule / content / application, something other than globally.&amp;nbsp;NSFR-I-22821&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When querying my account team about the traction of this request I have been advised it is still not on the roadmap as there has been little traction on it from other customer, even though the reality of it is the palo firewall is either not adequately able to enforce it's security policy or it is not able to provide access to many modern websites / streaming platforms or even it's own update service.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please ask your account teams to vote for this feature request.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2026 04:27:59 GMT</pubDate>
    <dc:creator>DaMonk</dc:creator>
    <dc:date>2026-07-27T04:27:59Z</dc:date>
    <item>
      <title>HTTP partial response - Security protection bypass</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/http-partial-response-security-protection-bypass/m-p/1260011#M7040</link>
      <description>&lt;P&gt;The Palo Firewall supports HTTP partial response and is enabled by default, best practice is to disable HTTP partial response but this is a global setting.&amp;nbsp; Doing so will break access to numerous internet based systems like youtube, and a number of other systems that utilise chuck encoding, including palo's own content updates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When&amp;nbsp;HTTP partial response is allowed, and&lt;SPAN&gt;&amp;nbsp;a download is blocked due to file blocking policy, AV signature etc, and it is hosted on a site that supports resumption (which is very common these days), a user can simply select resume and the file will be downloaded, even more of an issue is lately I have seen browsers automatically resume downloads, and a number of other solutions will automatically resume a failed download&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What is even worse is that the firewall logs will record the file was blocked, but not that the file was then successfully downloaded, so the logs are incorrect.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A feature request exists to either fix or enhance the ability to selectively block / allow&amp;nbsp;HTTP partial response based on rule / content / application, something other than globally.&amp;nbsp;NSFR-I-22821&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When querying my account team about the traction of this request I have been advised it is still not on the roadmap as there has been little traction on it from other customer, even though the reality of it is the palo firewall is either not adequately able to enforce it's security policy or it is not able to provide access to many modern websites / streaming platforms or even it's own update service.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please ask your account teams to vote for this feature request.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 04:27:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/http-partial-response-security-protection-bypass/m-p/1260011#M7040</guid>
      <dc:creator>DaMonk</dc:creator>
      <dc:date>2026-07-27T04:27:59Z</dc:date>
    </item>
  </channel>
</rss>

