<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mega service in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24344#M17743</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI, i totally agree with you, a combination o app-id and url-based rule is the winning strategic solution. But first of all an app-id has to be built, i've defined protocols and networks for a custom app but i prefer working with an offical one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;App-id cache pollution&amp;nbsp; was a nightmare in explaining to my customers and spamming youtube videos spred out panic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Jan 2013 16:18:03 GMT</pubDate>
    <dc:creator>NGS_SOC</dc:creator>
    <dc:date>2013-01-27T16:18:03Z</dc:date>
    <item>
      <title>Mega service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24342#M17741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is programmed a content update during next week for the new application mega (mega.co.nz)? &lt;/P&gt;&lt;P&gt;Right now the service is recognized as ssl, web-browing and unknown-tcp and becomes urget its new calssification due to the high bandwidth consumption and downloading legal issue. Brighcloud classifies correctly as personal storage but an application-based view, except from custom app, is required as soon as possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 11:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24342#M17741</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2013-01-27T11:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mega service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24343#M17742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think a combination of appid's with url-filter is always advisable specially when the domain(s) use a dedicated name and the application is http/https-based.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just compare with the app-id cache pollution during the xmas-holidays. If an url-filter had been used in combination with appid it would have been much harder to bypass the filter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 16:05:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24343#M17742</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-27T16:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Mega service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24344#M17743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI, i totally agree with you, a combination o app-id and url-based rule is the winning strategic solution. But first of all an app-id has to be built, i've defined protocols and networks for a custom app but i prefer working with an offical one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;App-id cache pollution&amp;nbsp; was a nightmare in explaining to my customers and spamming youtube videos spred out panic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 16:18:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24344#M17743</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2013-01-27T16:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mega service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24345#M17744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think currently the best option is to contact the appid team at reasearch center to get an official appid: &lt;A class="active_link" href="http://researchcenter.paloaltonetworks.com/tools/" title="http://researchcenter.paloaltonetworks.com/tools/"&gt;http://researchcenter.paloaltonetworks.com/tools/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And until their work hits the appid-db, as a workaround, create a custom-appid which will look at the host part of the http request (using web-browsing or such as a base-app) along with an url-filter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also dont forget the ssl-termination (dunno if Mega is compatible with this or not).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 16:47:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24345#M17744</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-27T16:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Mega service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24346#M17745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;Also dont forget the ssl-termination (dunno if Mega is compatible with this or not).&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you mean ssl decryption or a peculiar configuration upon custom app id?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 16:55:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24346#M17745</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2013-01-27T16:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Mega service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24347#M17746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Application mega build on app release 358&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Mar 2013 23:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24347#M17746</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2013-03-02T23:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Mega service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24348#M17747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for late response, I meant ssl decryption yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The one where the PA will terminate the ssl session and create another one towards Internet - the client must have the CA the PA device will use for the ssl session between PA box and the client as a trusted CA. However some applications refuses to have their SSL traffic terminated or inspected (like windowsupdate among others). I dont know if this is the case for mega aswell. The PA can do a light edition of inspection (or just logging that is) for ssl it cannot terminate (decrypt) and that is by looking at the CN record of the cert being used (used for url-filtering when ssl decrypt is not active).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best is to try to enable ssl decrypt and see how that works with mega (because then you can do stuff like IPS, AV, filetypes etc)...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Mar 2013 16:52:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mega-service/m-p/24348#M17747</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-03T16:52:50Z</dc:date>
    </item>
  </channel>
</rss>

