<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allowing ms-update on app-default, File blocking PE and therefore no windows updates in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/190656#M118</link>
    <description>&lt;P&gt;Go to Objects ,File Blocking and&amp;nbsp; create a new File Blocking policy.&amp;nbsp; In that policy add in Application ms-update&amp;nbsp; then the next tab File Types add PE and allow . Then Go to security policy in Polices the Security tab and create a rule for your WSUS server and make sure the file blocking policy in that rule is off or you use the new File Blocking policy you created.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Dec 2017 17:21:24 GMT</pubDate>
    <dc:creator>AndyYerger</dc:creator>
    <dc:date>2017-12-07T17:21:24Z</dc:date>
    <item>
      <title>Allowing ms-update on app-default, File blocking PE and therefore no windows updates</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/172896#M56</link>
      <description>&lt;P&gt;New PAN implementation and blocking per PA best practice (PE, multi-level, etc..) and allowing ms-update on application default. &amp;nbsp;However the WSUS server is not able to download any updates and its classifying a PE file as a threat. &amp;nbsp;The file in question is&amp;nbsp;am_delta_patch_1.249.1313.0_52b04aae0eb450654fc89884b43d10b7ed5 and threat-id is 52060 but nothing matches in the Threat Vault. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need a specific rule allowing windows updates that&amp;nbsp;allows PE files? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 18:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/172896#M56</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2017-08-23T18:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing ms-update on app-default, File blocking PE and therefore no windows updates</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/190656#M118</link>
      <description>&lt;P&gt;Go to Objects ,File Blocking and&amp;nbsp; create a new File Blocking policy.&amp;nbsp; In that policy add in Application ms-update&amp;nbsp; then the next tab File Types add PE and allow . Then Go to security policy in Polices the Security tab and create a rule for your WSUS server and make sure the file blocking policy in that rule is off or you use the new File Blocking policy you created.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 17:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/190656#M118</guid>
      <dc:creator>AndyYerger</dc:creator>
      <dc:date>2017-12-07T17:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing ms-update on app-default, File blocking PE and therefore no windows updates</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/238824#M456</link>
      <description>&lt;P&gt;it's can't solve the issue of MS-update&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 08:13:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/238824#M456</guid>
      <dc:creator>Randnabeel8</dc:creator>
      <dc:date>2018-11-07T08:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing ms-update on app-default, File blocking PE and therefore no windows updates</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/241757#M472</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yes a rule would help. Go to security policy in Polices the Security tab and create a rule for your WSUS server and make sure the file blocking policy in that rule is off . Then move that rule to the top of your security policies right under any block rules you may have in those policies.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Dec 2018 03:47:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/allowing-ms-update-on-app-default-file-blocking-pe-and-therefore/m-p/241757#M472</guid>
      <dc:creator>AndyYerger</dc:creator>
      <dc:date>2018-12-01T03:47:42Z</dc:date>
    </item>
  </channel>
</rss>

