<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking OS specific traffic? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20446#M14913</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;bgranholm schrieb:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We were thinking that we could just block them at the firewall but the firewall doesn't recognize OS that I know of.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;

&lt;/PRE&gt;&lt;P&gt;GlobalProtect knows the OS &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; So does the Firewall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Jun 2014 13:16:28 GMT</pubDate>
    <dc:creator>gafrol</dc:creator>
    <dc:date>2014-06-25T13:16:28Z</dc:date>
    <item>
      <title>Blocking OS specific traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20442#M14909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know if there is a way to block traffic sourced from a specific OS in our network?&lt;/P&gt;&lt;P&gt;We were discussing legacy Windows XP machines. Since they are no longer supported or being updated it would be nice to be able to block them from the internet but allow internal connections to them. (We have a couple of legacy programs we need to keep for customers that either dont exist any more or were never updated to run on anything but windows XP)&lt;/P&gt;&lt;P&gt;We were thinking that we could just block them at the firewall but the firewall doesn't recognize OS that I know of.&lt;/P&gt;&lt;P&gt;We could certainly give them static IPs and block them based on that but it would be nice to be able to block traffic to any Windows XP machine on our network just by virtue of its OS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jun 2014 13:55:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20442#M14909</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2014-06-24T13:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking OS specific traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20443#M14910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For web applications there is a user posted solution for detecting the Windows XP agent and blocking access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6948"&gt;Custom vulnerability signature for identifying Windows XP clients&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jun 2014 14:05:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20443#M14910</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-24T14:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking OS specific traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20444#M14911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Steven, that is perfect!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jun 2014 14:57:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20444#M14911</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2014-06-24T14:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking OS specific traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20445#M14912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if a user changes the user agent which isnt' rocket science then this won't work. this will also only work for web traffic. Look into global protect HIPS or Forescout which is a technology partner with Palo Alto Networks or a NAC solution if you want them off the network. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jun 2014 15:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20445#M14912</guid>
      <dc:creator>jkim2</dc:creator>
      <dc:date>2014-06-24T15:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking OS specific traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20446#M14913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;bgranholm schrieb:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We were thinking that we could just block them at the firewall but the firewall doesn't recognize OS that I know of.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;

&lt;/PRE&gt;&lt;P&gt;GlobalProtect knows the OS &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; So does the Firewall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jun 2014 13:16:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-os-specific-traffic/m-p/20446#M14913</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2014-06-25T13:16:28Z</dc:date>
    </item>
  </channel>
</rss>

