<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Brave Borwser in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/1224825#M123786</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;For blocking TOR, I would recommend two things:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use the External Dynamic List to block TOR traffic
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/external-dynamic-lists/enforce-policy-on-an-external-dynamic-list" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/external-dynamic-lists/enforce-policy-on-an-external-dynamic-list&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;There should be one for TOR exist nodes built in.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Only allow known applications:&lt;BR /&gt;
&lt;OL&gt;
&lt;LI&gt;SSL, HTTPs, etc.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 26 Mar 2025 17:09:11 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2025-03-26T17:09:11Z</dc:date>
    <item>
      <title>Block Brave Borwser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/460843#M102116</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have noticed that some of our employees are using a brave browser and can easily open blocked websites like Facebook, crypto, games etc. what's the way to block brave browsers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 08:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/460843#M102116</guid>
      <dc:creator>HilalWani</dc:creator>
      <dc:date>2022-01-25T08:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block Brave Borwser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/460904#M102121</link>
      <description>&lt;P&gt;Maybe write an application signature that matches the User-Agent header. you can use as an examples:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/use-application-objects-in-policy/create-a-custom-application.html" target="_blank" rel="noopener"&gt;Create a Custom Application (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRoCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRoCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My article for referer header but the principle is the same, just find what is the User-agent string for the browser you want to block:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/automation-api-discussions/knowledge-sharing-version-10-no-7-byte-limit-for-sinatures/m-p/394734#M2600" target="_blank" rel="noopener"&gt;LIVEcommunity - Knowledge sharing: Version 10 no 7 byte limit for sinatures examples for Layer 7 (L7) DDOS/Brute force protection and referer match - LIVEcommunity - 394734 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Better if you have EDR/Endpoint Protection or Active Directory to block and delete the browser software on the endpoints themselves.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 14:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/460904#M102121</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-01-25T14:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Block Brave Borwser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/461073#M102131</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195451"&gt;@HilalWani&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Don't use the firewall to do something it wasn't ever designed to do. User-Agent strings are just that, strings, easily modified in any browser to bypass any restriction you put in place. If your employees are already using Brave to bypass filtering you can also ensure that they'll quickly find out you can modify the User-Agent string to whatever they want and bypass your block.&lt;/P&gt;
&lt;P&gt;Instead, do as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;mentioned at the tale end of his post and use something on the endpoint to block installation of Brave outright. If you have utilize Windows and Active Directory you can easily activate AppLocker and block any publisher you want through AppLocker rules and GPO. Intune and other MDMs can do the same, and the vast majority of Antivirus or EDR solutions can do the exact same thing as long as you have something actively installed and managing these endpoints.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 03:48:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/461073#M102131</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-26T03:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block Brave Borwser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/461122#M102134</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i think the employees use the "Tor Tabs" Feature. see &lt;A href="https://brave.com/privacy-features/" target="_blank"&gt;https://brave.com/privacy-features/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So your approach should not to "Block Brave" but Block Tor connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 10:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/461122#M102134</guid>
      <dc:creator>JGriessmeier</dc:creator>
      <dc:date>2022-01-26T10:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Block Brave Borwser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/461125#M102136</link>
      <description>&lt;P&gt;Coudl you please show me how can i block Tor&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 12:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/461125#M102136</guid>
      <dc:creator>HilalWani</dc:creator>
      <dc:date>2022-01-26T12:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Block Brave Borwser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/1224582#M123751</link>
      <description>&lt;P&gt;To effectively block the TOR network on firewalls, you can use EDL, I have left a list from the Tor project&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.dan.me.uk/torlist/" target="_blank"&gt;https://www.dan.me.uk/torlist/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Block the above list using EDL (external Dynamic list) with an update period of every 24 hours.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 14:49:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/1224582#M123751</guid>
      <dc:creator>Paulo_Cesar_Saboia</dc:creator>
      <dc:date>2025-03-24T14:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Block Brave Borwser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/1224824#M123785</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would not recommend a custom application as this disabled a lot of the real-time active threat scanning for that policy its applied to. You can instead block applications that are already existing to prevent its use. I know that it uses DNS over HTTPs so blocking that should prevent most users.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1743008542695.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66790i1F6AD51FCF4C2E1B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1743008542695.png" alt="OtakarKlier_0-1743008542695.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also enabling SSL decryption and URL filtering should block most features and destinations the users are attempting to access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 17:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/1224824#M123785</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-03-26T17:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Block Brave Borwser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/1224825#M123786</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;For blocking TOR, I would recommend two things:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use the External Dynamic List to block TOR traffic
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/external-dynamic-lists/enforce-policy-on-an-external-dynamic-list" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/external-dynamic-lists/enforce-policy-on-an-external-dynamic-list&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;There should be one for TOR exist nodes built in.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Only allow known applications:&lt;BR /&gt;
&lt;OL&gt;
&lt;LI&gt;SSL, HTTPs, etc.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 17:09:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-brave-borwser/m-p/1224825#M123786</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-03-26T17:09:11Z</dc:date>
    </item>
  </channel>
</rss>

