<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict the user agent on Palo Alto firewall in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/71341#M1195</link>
    <description>&lt;P&gt;The pattern for chrome used says only "&lt;SPAN&gt;Pattern:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Chrome/"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;We try to do the same but for internet explorer.&lt;/P&gt;
&lt;P&gt;We want to allow Chrome but not Internet Explorer.&lt;/P&gt;
&lt;P&gt;What "Pattern: " should we use ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should we be looking at user-agent ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jan 2016 11:13:31 GMT</pubDate>
    <dc:creator>Mariusz.pianka</dc:creator>
    <dc:date>2016-01-21T11:13:31Z</dc:date>
    <item>
      <title>Restrict the user agent on Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/12048#M322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp; We have a requirement to restrict the user agent through palo alto firewall.For example allow web-browsing only from internet explorer 10 and not from any other version of IE or from any other browser like firefox or google chrome.Kindly advise this is possible and how&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Anvar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2015 07:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/12048#M322</guid>
      <dc:creator>Soc-Core42</dc:creator>
      <dc:date>2015-01-13T07:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict the user agent on Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/12049#M323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/31624"&gt;injazat-soc&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you go through this document: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1247"&gt;How to Block Google Chrome&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look for the user-agent for IE 10 requests and allow that application only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2015 07:28:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/12049#M323</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2015-01-13T07:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict the user agent on Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/12050#M324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;injazat-soc,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently do not have any defined applications for Internet Explorer, Google Chrome or Firefox.&amp;nbsp; I have seen it setup where Google Chrome can be blocked, due to a custom signature that you can create, as mentioned above by @bat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We could make a rule to allow Internet Explorer only, once we create a signature that will trigger the rule, yet we would also have to create another 'deny' rule to block every other browser.&amp;nbsp; So to accomplish this, we are looking at creating a signature for almost every browser you can think of, in order to allow traffic only to Internet Explorer. To go a step further, we would have to determine how to create a signature that could differentiate between browser version, which may not be viable. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall is unaware of the browser the user will be browsing the internet with. It only knows that it is passing traffic on port 80, or 443. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clarified a few things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do not forget to mark any 'helpful' or 'correct' answers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2015 08:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/12050#M324</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-01-13T08:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict the user agent on Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/71341#M1195</link>
      <description>&lt;P&gt;The pattern for chrome used says only "&lt;SPAN&gt;Pattern:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Chrome/"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;We try to do the same but for internet explorer.&lt;/P&gt;
&lt;P&gt;We want to allow Chrome but not Internet Explorer.&lt;/P&gt;
&lt;P&gt;What "Pattern: " should we use ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should we be looking at user-agent ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2016 11:13:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/71341#M1195</guid>
      <dc:creator>Mariusz.pianka</dc:creator>
      <dc:date>2016-01-21T11:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict the user agent on Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/73849#M1200</link>
      <description>&lt;P&gt;Hi Mariusz,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes, you should be looking at user agent strings. You have a pretty good list here to start with: &lt;A href="http://useragentstring.com/pages/useragentstring.php" target="_blank"&gt;http://useragentstring.com/pages/useragentstring.php&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to block "all" browsers, just those that might be installed onto your systems, right? If that is corporate or whatever domained environment, you need to block several versions of IE explorer that preceed IE10, so you need to add five-six "OR" rules to a first example like that one with Chrome, and your agent lists need to have at least 7 characters. You can do that with blocking separately "MSIE\ 6\.", than "MSIE\ 5.", whatever - 7, 8, 4, 3 2. You have 7 characters there, "MSIE 6." but you are escaping blank space and dot with backspace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: I just re-read your last question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you want to block just IE, you can do that with "atible;\ MSIE" - will do the trick to catch (m)any versions of IE. If not, see what you have and play with it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have somewhat technical document here: &lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Creating-Custom-Threat-Signatures/ta-p/58569" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Creating-Custom-Threat-Signatures/ta-p/58569&lt;/A&gt; that describes all your possibilities for matching (you are specifically matching here a "http-req-headers" that is described in that document) and at the end of the document you can find an explanation on regular expressions that are used for pattern-match.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Mon, 29 Feb 2016 22:54:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/restrict-the-user-agent-on-palo-alto-firewall/m-p/73849#M1200</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-02-29T22:54:49Z</dc:date>
    </item>
  </channel>
</rss>

