<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem Blockin Linkedin - What is the best practice ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24784#M18064</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Essilobr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screenshot would help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Mar 2013 15:00:11 GMT</pubDate>
    <dc:creator>wesa</dc:creator>
    <dc:date>2013-03-21T15:00:11Z</dc:date>
    <item>
      <title>Problem Blockin Linkedin - What is the best practice ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24783#M18063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am stuck with this problem since the lasts 2 weeks...&lt;/P&gt;&lt;P&gt;We have a default rule in our company blocking any social networking, but for some HR users, linkedin should be allowed.&lt;/P&gt;&lt;P&gt;I am trying to make a rule to allow some users to access only the linkedin website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Decided this way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source zone &amp;gt; trust&lt;/P&gt;&lt;P&gt;src add &amp;gt; any&lt;/P&gt;&lt;P&gt;user &amp;gt; specific user&lt;/P&gt;&lt;P&gt;dst zone &amp;gt; untrust&lt;/P&gt;&lt;P&gt;destination add &amp;gt; FQDN objetcts ".linkedin.com" and ".licdn.com"&lt;/P&gt;&lt;P&gt;application &amp;gt; linkedin ssl&lt;/P&gt;&lt;P&gt;service &amp;gt; any&lt;/P&gt;&lt;P&gt;profile &amp;gt; none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Results&lt;/P&gt;&lt;P&gt;I can open the page but that is not well formatted...&lt;/P&gt;&lt;P&gt;In monitor &amp;gt; url filtering I see that traffic going to &lt;/P&gt;&lt;P&gt;"s.c.lnkd.licdn.com/scds/concat/common/js........"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is not being recognized at this "allow linkedin rule" then traffic got blocked in the end (where social-networking traffic is blocked by default)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- How would be the best practice to get this problem solved ?&lt;/P&gt;&lt;P&gt;- Is the FQDN objects correct ?&lt;/P&gt;&lt;P&gt;- why FQDN object ".linkedin.com" is OK but ".licdn.com" is not ok ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any reply... if you guys want some screens shots I can provide as well... thanks thanks thanks!&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 14:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24783#M18063</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2013-03-21T14:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem Blockin Linkedin - What is the best practice ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24784#M18064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Essilobr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screenshot would help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 15:00:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24784#M18064</guid>
      <dc:creator>wesa</dc:creator>
      <dc:date>2013-03-21T15:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Problem Blockin Linkedin - What is the best practice ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24785#M18065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you use FQDN what happens is the mp resolves the domain listed in the fqdn and lists the ip addresses so this fqdn is related to the ip's belonging to linkedin and not the actual url that you visit.&lt;/P&gt;&lt;P&gt;So i would suggest using www.linkedin.com under fqdn's and use a url category/profile with s.c.lnkd.licdn.com/*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 18:28:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24785#M18065</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-03-21T18:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Problem Blockin Linkedin - What is the best practice ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24786#M18066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We found out that apps LINKEDIN uses SSL, but that dependencies is not yet mapped by Palo Alto... that was the problem....&lt;/P&gt;&lt;P&gt;If we check at applipedia, linkedin apps only has web-browser dependencie... and during the initial authentication, the site uses ssl.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then we solve the problem creating 2 rules as per below image&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot540.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6097_ScreenShot540.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;1st one an rule allow some users to any destination but only for app LINKEDIN&lt;/P&gt;&lt;P&gt;after the first access (www.linkedin.com) users will login... that time an application shift will occur (from linedin to ssl)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2nd rule allows that same users go to specific destination FQDN (www.linkedin.com) with app ssl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That worked for us....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe later when PA realize that they need to put SSL as a default dependency for linkedin app... maybe I can delete the 2nd rule... by now we need that...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks everyone who helped us!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 15:37:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-blockin-linkedin-what-is-the-best-practice/m-p/24786#M18066</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2013-03-27T15:37:01Z</dc:date>
    </item>
  </channel>
</rss>

