<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I want to allow gmail access to specific users on my LAN segment. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/i-want-to-allow-gmail-access-to-specific-users-on-my-lan-segment/m-p/643748#M122134</link>
    <description>&lt;P&gt;I have created a policy which says "Src: FQDN of 2users" "DST:Any" "App: gmail-base, gmail-posting, ssl, stun, vidyo, web-browsing" "URL CATEGORY: Computer and internet info, web-based-email" "Action: Allow"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But the logs I see is, those users are not hitting this policy (They are still passing through the default policy even the above created policy is above the default one) and "Session-End-Rease: Threat".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically what I understand is that L7 inspection is blocking the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need help...&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2024 11:19:01 GMT</pubDate>
    <dc:creator>S.Muhammad477648</dc:creator>
    <dc:date>2024-11-21T11:19:01Z</dc:date>
    <item>
      <title>I want to allow gmail access to specific users on my LAN segment.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-want-to-allow-gmail-access-to-specific-users-on-my-lan-segment/m-p/643748#M122134</link>
      <description>&lt;P&gt;I have created a policy which says "Src: FQDN of 2users" "DST:Any" "App: gmail-base, gmail-posting, ssl, stun, vidyo, web-browsing" "URL CATEGORY: Computer and internet info, web-based-email" "Action: Allow"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But the logs I see is, those users are not hitting this policy (They are still passing through the default policy even the above created policy is above the default one) and "Session-End-Rease: Threat".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically what I understand is that L7 inspection is blocking the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need help...&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 11:19:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-want-to-allow-gmail-access-to-specific-users-on-my-lan-segment/m-p/643748#M122134</guid>
      <dc:creator>S.Muhammad477648</dc:creator>
      <dc:date>2024-11-21T11:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: I want to allow gmail access to specific users on my LAN segment.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-want-to-allow-gmail-access-to-specific-users-on-my-lan-segment/m-p/644771#M122149</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1157100811"&gt;@S.Muhammad477648&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I would generally recommend creating a much more targeted policy. The firewall can easily identify Gmail traffic just through app-id regardless of whether or not you're actually decrypting that traffic or not. So you could just build a rule for those two users targeted app-id and utilize the container 'gmail' application if you wanted. I wouldn't utilize the URL categories that you have specified at all. Either build one specific to Google or exclude it from your policy outright.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once that is done if it's still not matching you will need to ensure that your FQDN objects are resolving properly and actually take a detailed look at your logs.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 19:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-want-to-allow-gmail-access-to-specific-users-on-my-lan-segment/m-p/644771#M122149</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-11-21T19:48:10Z</dc:date>
    </item>
  </channel>
</rss>

