<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Access to private Gmail but allow corporate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/443039#M100167</link>
    <description>&lt;P&gt;Step 1 Make sure you are decrypting traffic from the inside to the outside&lt;/P&gt;&lt;P&gt;Step 2 Create a custom URL with *.google.com and *.gmail.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hectormorrell_0-1634946868945.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37220i38AC6869EDF618E6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Hectormorrell_0-1634946868945.png" alt="Hectormorrell_0-1634946868945.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Step 3 Create a URL FILTER &amp;nbsp;&lt;/P&gt;&lt;P&gt;Select HTTP HEADER Insertion&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Called it GMAIL-GOOGLE&amp;nbsp; Type Google apps Access control&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Under domain add the following *.google.com and gmail.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select header X-GooApps-Allowed domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Under value add your corporate domain example.com paloaltonetworks.com etc&lt;/P&gt;&lt;P&gt;You can add 5 domains&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hectormorrell_1-1634946868950.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37217iDCF478376EB3EA49/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Hectormorrell_1-1634946868950.png" alt="Hectormorrell_1-1634946868950.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hectormorrell_2-1634946868954.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37219iE5DF63EB66F237C8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Hectormorrell_2-1634946868954.png" alt="Hectormorrell_2-1634946868954.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;STEP 4 create a policy&lt;/P&gt;&lt;P&gt;INSIDE-2-OUTSIDE&amp;nbsp;&amp;nbsp; Inside outside APPS GOOGLE-APPS service URL Category=GMAIL-COORPORATE Action= allow profile=url Filtering =GMAIL-FILTER&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GOOGLE-APPS= GMAIL, Google-BASE, ssl, RTCP,rtp-base,stun,web-browsing vidyo&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Oct 2021 23:54:47 GMT</pubDate>
    <dc:creator>Hectormorrell</dc:creator>
    <dc:date>2021-10-22T23:54:47Z</dc:date>
    <item>
      <title>Block Access to private Gmail but allow corporate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/195686#M58409</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;Im looking for a solution to block user access to private gmail accounts but allow a corporate accounts to be used.&lt;/P&gt;&lt;P&gt;I'm aware that there is a solution involing proxy server and X-forwarder.&lt;/P&gt;&lt;P&gt;Is there any other way to do this without dedicated proxy serever?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 10:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/195686#M58409</guid>
      <dc:creator>Leonid.Rozgon</dc:creator>
      <dc:date>2018-01-18T10:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Block Access to private Gmail but allow corporate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/195720#M58413</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56954"&gt;@Leonid.Rozgon&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't tested this myself but you could try the following :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If I'm not mistaken for corporate Gmail access, the usernames have the customer domain name (&lt;FONT color="#000000"&gt;eg.&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT color="#000000"&gt;user@domain.com).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Personal Gmail accounts have usual usernames (eg.&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#000000"&gt;user@gmail.com)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To block personal gmail access, enable ssl-decryption.&amp;nbsp; Next,&amp;nbsp;create a data pattern matching "@gmail.com".&lt;/P&gt;
&lt;P&gt;Match this Data pattern&amp;nbsp;on gmail-base app in a Data filtering object.&lt;/P&gt;
&lt;P&gt;Apply the Data Filtering object to a policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This way you should be able to access corporate gmail accounts&amp;nbsp;and personal gmail access&amp;nbsp;should be blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One caveat I think exists here :&lt;/P&gt;
&lt;P&gt;Matching for the regex "@gmail\.com" in the whole page content might also have unwanted matches such as :&lt;/P&gt;
&lt;P&gt;-Sending an email to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;somebody@gmail.com&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;from the corporate account&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Reading an email from&amp;nbsp;&lt;/SPAN&gt;somebody@gmail.com&lt;SPAN&gt;&amp;nbsp;on&amp;nbsp;the corporate account&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would think along those lines ... other tips are welcome ^_^&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 12:52:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/195720#M58413</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-01-18T12:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Block Access to private Gmail but allow corporate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/195738#M58415</link>
      <description>&lt;P&gt;Thanks for the idea, Kiwi.&lt;/P&gt;&lt;P&gt;Trying to test/implement it, but I think the problem is that there is no option to add&amp;nbsp;&lt;STRONG&gt;ssl &lt;/STRONG&gt;or&amp;nbsp;&lt;STRONG&gt;google-base&lt;/STRONG&gt;&amp;nbsp;as application in Data filtering profile(whys is that?). Authentication form for gmail is done through&amp;nbsp;accounts.google.com and its not detected as gmail-base application. Will continue testing. If anyone else have any ideas feel free to wite them here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 796px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13294i6998EFECAE80C6CB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 14:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/195738#M58415</guid>
      <dc:creator>Leonid.Rozgon</dc:creator>
      <dc:date>2018-01-18T14:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Block Access to private Gmail but allow corporate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/332575#M84071</link>
      <description>&lt;P&gt;Were you able to find anything out? I know Google has a way to block it on Chrome OS devices.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 15:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/332575#M84071</guid>
      <dc:creator>Tuna20</dc:creator>
      <dc:date>2020-06-09T15:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Block Access to private Gmail but allow corporate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/443039#M100167</link>
      <description>&lt;P&gt;Step 1 Make sure you are decrypting traffic from the inside to the outside&lt;/P&gt;&lt;P&gt;Step 2 Create a custom URL with *.google.com and *.gmail.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hectormorrell_0-1634946868945.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37220i38AC6869EDF618E6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Hectormorrell_0-1634946868945.png" alt="Hectormorrell_0-1634946868945.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Step 3 Create a URL FILTER &amp;nbsp;&lt;/P&gt;&lt;P&gt;Select HTTP HEADER Insertion&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Called it GMAIL-GOOGLE&amp;nbsp; Type Google apps Access control&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Under domain add the following *.google.com and gmail.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select header X-GooApps-Allowed domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Under value add your corporate domain example.com paloaltonetworks.com etc&lt;/P&gt;&lt;P&gt;You can add 5 domains&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hectormorrell_1-1634946868950.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37217iDCF478376EB3EA49/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Hectormorrell_1-1634946868950.png" alt="Hectormorrell_1-1634946868950.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hectormorrell_2-1634946868954.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37219iE5DF63EB66F237C8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Hectormorrell_2-1634946868954.png" alt="Hectormorrell_2-1634946868954.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;STEP 4 create a policy&lt;/P&gt;&lt;P&gt;INSIDE-2-OUTSIDE&amp;nbsp;&amp;nbsp; Inside outside APPS GOOGLE-APPS service URL Category=GMAIL-COORPORATE Action= allow profile=url Filtering =GMAIL-FILTER&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GOOGLE-APPS= GMAIL, Google-BASE, ssl, RTCP,rtp-base,stun,web-browsing vidyo&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 23:54:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/443039#M100167</guid>
      <dc:creator>Hectormorrell</dc:creator>
      <dc:date>2021-10-22T23:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block Access to private Gmail but allow corporate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/443096#M100173</link>
      <description>&lt;P&gt;Group.. i would recommend that the customer look at HTTP Header Insertion n under the URL Filter Profile section&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/app-id-features/http-header-insertion.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/app-id-features/http-header-insertion.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the HTTP header insertion and modification feature, you can now manage HTTP header information to disallow SaaS consumer accounts while allowing a specific enterprise account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Oct 2021 12:00:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/m-p/443096#M100173</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-10-23T12:00:02Z</dc:date>
    </item>
  </channel>
</rss>

