<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application Blocking in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27010#M19732</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I originally had the app block in our blacklist firewall rule. Because we had manual addresses entered to the blacklist firewall rule, the app block only was blocking for those previous blacklisted IP Addresses. I basically turned off my blacklist for a couple days :smileyblush::smileyconfused::smileycry:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Thanks to Steven Puluka for the assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We now have a dedicated firewall rule for nothing but apps. Any-Any traffic. Unfortunately the torch block is still not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I am successfully able to navigate to torchbrowser.com&lt;/LI&gt;&lt;LI&gt;Download &amp;amp; Install the torch browser.exe&lt;/LI&gt;&lt;LI&gt;Use the torch browser to access the internet. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My logs are showing me with denies for when using torch. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="2a.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19223_2a.PNG" style="height: 361px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;But I'm still able to freely browse the internet? (Obviously not to follow the Cubs, &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2b.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19224_2b.PNG" style="height: 506px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;So can anyone from PAN talk about what is actually being blocked here? Maybe some of the Torch app functions? In my opinion this block is almost worthless. I'm not sure if its going to be worth the time in researching other apps to potentionally block, unless they are actually completely "blocked".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Justin&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Apr 2015 19:31:49 GMT</pubDate>
    <dc:creator>Rags</dc:creator>
    <dc:date>2015-04-17T19:31:49Z</dc:date>
    <item>
      <title>Application Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27006#M19728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear PAN Discussion Forum,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I come to you in dire need of assistance. There is a battle going on within my network realm. A battle that we are losing. Some of my people have been mislead by downloading the Torch Browser application, and are now infected!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Torch Browser. Sucks in my users with an edgy-cool looking website that shows its fun to use, with all of it's add-on's and features. Unfortunately, media downloads, torrents, games, etc aren't allowed on our network, and this needs to be stopped!&lt;/P&gt;&lt;P&gt;&lt;IMG alt="torch.PNG" class="image-0 jive-image" height="213" src="https://live.paloaltonetworks.com/legacyfs/online/19174_torch.PNG" style="height: 213.3px; width: 474px;" width="474" /&gt;&lt;/P&gt;&lt;P&gt;We have located the coordinates of our enemy:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="torch-ip.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19181_torch-ip.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;We have captured one of them to find out more information:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="torchexe.PNG" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/19182_torchexe.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="torchb1.PNG" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/19183_torchb1.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Torchb3.PNG" class="jive-image image-4" height="110" src="https://live.paloaltonetworks.com/legacyfs/online/19184_Torchb3.PNG" style="height: 110.283870967742px; width: 407px;" width="407" /&gt;&lt;/P&gt;&lt;P&gt;We have build some defenses to try and stop the Torch attack, but we have been unsuccessful, we are too weak!!!&lt;/P&gt;&lt;P&gt;&lt;IMG alt="appblock2.PNG" class="jive-image image-5" src="https://live.paloaltonetworks.com/legacyfs/online/19185_appblock2.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="appblock1.PNG" class="jive-image image-6" height="263" src="https://live.paloaltonetworks.com/legacyfs/online/19186_appblock1.PNG" style="height: 263px; width: 507.214285714286px;" width="507" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="torchaaa.PNG" class="image-10 jive-image" height="112" src="https://live.paloaltonetworks.com/legacyfs/online/19190_torchaaa.PNG" style="font-size: 13.3333330154419px; height: 112px; width: 1197.24137931034px;" width="1197" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first our enemy did not appear as the Torch Browser (Application = incomplete, web-browsing)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="torch1.PNG" class="jive-image image-8" height="476" src="https://live.paloaltonetworks.com/legacyfs/online/19188_torch1.PNG" style="height: 475.548387096774px; width: 945px;" width="945" /&gt;&lt;/P&gt;&lt;P&gt;When you have Torch Browser open, some of the traffic calls to 54.239.18.49.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We were able to confirm this was the Torch Browser for the Application! But they are still getting past our defenses!&lt;/P&gt;&lt;P&gt;Application = torch-browser-base&lt;/P&gt;&lt;P&gt;&lt;IMG alt="torch7.PNG" class="jive-image image-9" height="488" src="https://live.paloaltonetworks.com/legacyfs/online/19189_torch7.PNG" style="height: 487.979381443299px; width: 966px;" width="966" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="allowed.PNG" class="jive-image image-11" src="https://live.paloaltonetworks.com/legacyfs/online/19191_allowed.PNG" style="height: 330px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;So at this point I'm not sure what to do, or if I even am doing the app blocks correctly.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Can I directly add applications to security policy block rules, or do I need to add them to an application-filter first?&lt;/LI&gt;&lt;LI&gt;Hard to tell if this is an issue with my firewall rules or if Torch Browser has changed, and PAN hasn't updated the App signatures for it recently?&lt;/LI&gt;&lt;LI&gt;I confirmed the Torch traffic is port 80, so I should not have to enable SSL decryption&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please, we are losing this battle. Please summon the Demi-Gods!!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, -Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 16:21:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27006#M19728</guid>
      <dc:creator>Rags</dc:creator>
      <dc:date>2015-04-14T16:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27007#M19729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great post, Justin. Thanks for the details and the laughs &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, so to address a few things first:&lt;/P&gt;&lt;P&gt;1. You can add applications directly to security policy block rules. Some people prefer app filters, because then if something new gets added the rule is updated, but it's just fine to do it either way.&lt;/P&gt;&lt;P&gt;2. Just about every application has some changes, but not often to the base functionality of them. Adding a block for the Torch Browser (via the "torch-browser" application) should block the clients.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;3. Port 80 does not equate to unencrypted, that's old-school port-based firewall logic rearing its ugly head. Torch isn't encrypted, so you're good, I just wanted to call out that ports don't automatically indicate the transport.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't have the full security rule, but your block screenshot (6th screenshot) looks like it's blocking Bitcoin or Torch, on any port. That should be fine, and while I haven't tested it there may have been a very recent app change. The rule that you blanked out in your final screenshot should tell you what rule is allowing the action. Is it possible that your block rule is below that rule so that the block doesn't have a chance to take effect? Are you getting any shadowing warnings when you commit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fare thee well on your battle.&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 23:11:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27007#M19729</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-04-14T23:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27008#M19730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume your block rule for the applications is above the allow rule.&amp;nbsp; Is the rest of the rule using any source/destination and zones?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs that do not identify the torch application (incomplete) will not be blocked.&amp;nbsp; there was not enough of a match in the pcap to categorize this for that purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume the rule that is permitting the matched traffic after the block rule?&amp;nbsp; If so, we need to determine why the traffic is failing to match the block rule criteria.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 23:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27008#M19730</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-04-14T23:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27009#M19731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help gwesson &amp;amp; Steven. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Apr 2015 13:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27009#M19731</guid>
      <dc:creator>Rags</dc:creator>
      <dc:date>2015-04-15T13:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27010#M19732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I originally had the app block in our blacklist firewall rule. Because we had manual addresses entered to the blacklist firewall rule, the app block only was blocking for those previous blacklisted IP Addresses. I basically turned off my blacklist for a couple days :smileyblush::smileyconfused::smileycry:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Thanks to Steven Puluka for the assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We now have a dedicated firewall rule for nothing but apps. Any-Any traffic. Unfortunately the torch block is still not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I am successfully able to navigate to torchbrowser.com&lt;/LI&gt;&lt;LI&gt;Download &amp;amp; Install the torch browser.exe&lt;/LI&gt;&lt;LI&gt;Use the torch browser to access the internet. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My logs are showing me with denies for when using torch. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="2a.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19223_2a.PNG" style="height: 361px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;But I'm still able to freely browse the internet? (Obviously not to follow the Cubs, &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2b.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19224_2b.PNG" style="height: 506px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;So can anyone from PAN talk about what is actually being blocked here? Maybe some of the Torch app functions? In my opinion this block is almost worthless. I'm not sure if its going to be worth the time in researching other apps to potentionally block, unless they are actually completely "blocked".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Justin&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2015 19:31:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27010#M19732</guid>
      <dc:creator>Rags</dc:creator>
      <dc:date>2015-04-17T19:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27011#M19733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The torch application has several components, one of which is a standard web browser. The web browser functions are no different than other browsers (Torch is actually a fork from the Chromium project, like Chrome and Safari) so there would be no reason to block that feature. Additionally, it can be a challenge since some browser plugins will allow the user-agent header to be modified. Without a hook into the OS, there would be no real way to see the actual application that made the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The torch functions that would be blocked are the features unique to it. Additionally, the built-in games and music functions have their own sub-app which would also be blocked if you block the main "torch-browser" app in your security rules, or can be blocked without blocking the other functions of the application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you block the torch-browser application in your security rules, it will effectively turn the torch browser into a standard web browser. It's rare that I hear specific browsers being blocked (like, allowing Chrome but denying Firefox), so that should be effective for what you're trying to achieve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to actually block the download and install of the Torch Browser client, that can be done with a custom URL filter (torchbrowser.com is classified as Computer and Internet, so blocking that whole category would be overkill). Downloading exe files can be restricted with a file blocking profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using the Torch browser and going through a security rule which blocks that app, are you able to actually use the music functions or game functions? If so, that would be unexpected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg Wesson&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2015 20:25:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27011#M19733</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-04-17T20:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27012#M19734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://live.paloaltonetworks.com/u1/11884"&gt;gwesson&lt;/A&gt; I'm going to mark your answer as the Correct Answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wasn't looking at it that way. I thought it would block everything from the URL, exe, anything in the packet that included torch information, etc. I guess I can block torch.exe with some of our security endpoint tools. Yes, I'm aware of what we can do with the URL blocks as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't test the apps within Torch, but I can tell by my logs that some of the torch features are being blocked because the outbound traffic is being stopped. Everything you do in Torch is probably logged and sent back to Torch. So at least that will be denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the explanation.&amp;nbsp; -Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2015 20:37:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking/m-p/27012#M19734</guid>
      <dc:creator>Rags</dc:creator>
      <dc:date>2015-04-17T20:37:40Z</dc:date>
    </item>
  </channel>
</rss>

