<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allowing Microsoft and Java Updates in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32412#M23752</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your file block profile you can add allow download for application MS-Update above you block and you will be able to download the updates. Java may be a little harder as there is not application in the file blocking profile.&amp;nbsp; You may want to contact you SE to submit a feature request to allow Java-updates as an application for file blocking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also make a rule above your current rule with no file block profile allow web-browsing to Sun's servers to get the downloaded files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I change rule 1 to allow application ms-update +&amp;nbsp; allow .exe (this would be 'and')&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 May 2011 23:05:44 GMT</pubDate>
    <dc:creator>dburns</dc:creator>
    <dc:date>2011-05-04T23:05:44Z</dc:date>
    <item>
      <title>Allowing Microsoft and Java Updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32411#M23751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to allow downloads of .exe and PE files for updates but continue to block users from downloading those file types from other sources.&amp;nbsp; Not sure what the best way to do this is.&lt;/P&gt;&lt;P&gt;If I build a file filter with 3 rules like:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; allow application ms-update&lt;/P&gt;&lt;P&gt;2. block .exe&lt;/P&gt;&lt;P&gt;3. allow any&lt;/P&gt;&lt;P&gt;Are these rules evaluated in sequential order? Or will the block .exe override the allow ms-update?&lt;/P&gt;&lt;P&gt;If I change rule 1 to allow application ms-update +&amp;nbsp; allow .exe&lt;/P&gt;&lt;P&gt;Would those variables (the app and the filetype) be And'ed or Or'd together?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another way I've tried to do this was to allow the application ms-updates in the firewall prior to URL filtering, but I get warnings that I need web-browsing enabled for the rule to work.&amp;nbsp; If I enable web-browsing in the same firewall rule I start to see browsing passing that rule instead of my service-http rules, although some traffic still gets down to the normal URL rules.&lt;/P&gt;&lt;P&gt;So what's the best way to go about this?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 May 2011 16:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32411#M23751</guid>
      <dc:creator>khaldeman</dc:creator>
      <dc:date>2011-05-04T16:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Microsoft and Java Updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32412#M23752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your file block profile you can add allow download for application MS-Update above you block and you will be able to download the updates. Java may be a little harder as there is not application in the file blocking profile.&amp;nbsp; You may want to contact you SE to submit a feature request to allow Java-updates as an application for file blocking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also make a rule above your current rule with no file block profile allow web-browsing to Sun's servers to get the downloaded files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I change rule 1 to allow application ms-update +&amp;nbsp; allow .exe (this would be 'and')&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 May 2011 23:05:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32412#M23752</guid>
      <dc:creator>dburns</dc:creator>
      <dc:date>2011-05-04T23:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Microsoft and Java Updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32413#M23753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running version 4.0.2.&lt;/P&gt;&lt;P&gt;I continue to have problems with ms-updates being blocked, specificially windows PE files.&amp;nbsp; I see the block in Data Filtering Log, so from the details of the block log I see that it is passing the URL filter with the appropriate file blocking ruleset.&amp;nbsp; I'm not sure if the file blocking builder screen is incomplete or not, but I find it strange that you should be able to sort the rules by name or other rather than the sequential order drag and drop mechanism of the other firewall rule screens.&amp;nbsp; I've named my rules alphebetically and sorted by name (a-z).&amp;nbsp; They appear on the main File Blocking screen in correct order.&amp;nbsp; I've also looked at the Config Audit screen to see if they were ordered properly in the config file.&amp;nbsp; They were, but for some reason even though the log shows that the application type was ms-update and the file was a Win PE file, it was still denied.&amp;nbsp; I've even seperated all file types into their own rule (ie. ms-update+PE,&amp;nbsp; ms-update.exe, ms-update.cab) and combined them.&amp;nbsp; Both with the same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions or should I start a ticket?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 17:23:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32413#M23753</guid>
      <dc:creator>khaldeman</dc:creator>
      <dc:date>2011-05-05T17:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Microsoft and Java Updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32414#M23754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Im trying to achieve the same goal, did you ever get a resolve? file blocking profile with allow EXE from ms-update etc does not work. Could use FQDN however was wondering what you managed to find out. thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ps, on PANO 4.0.5&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 21:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32414#M23754</guid>
      <dc:creator>wayne_webner</dc:creator>
      <dc:date>2011-09-22T21:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Microsoft and Java Updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32415#M23755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you checked the log what file type has been blocked? Have you tried to allow MS-Update as the app and allow all file types to see what file type actually we have allowed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jones &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 06:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32415#M23755</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-23T06:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Microsoft and Java Updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32416#M23756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I never could get it to work the way I was thinking in my head, but I did get it&amp;nbsp; to work an easier way.&lt;BR /&gt;&lt;BR /&gt;Rather than allowing at the file level, I am&amp;nbsp; allowing at the app level.&lt;BR /&gt;So under Policies-&amp;gt;Security as a rule above my&amp;nbsp; user http/https rules I have a rule called updates&lt;BR /&gt;In that rule I allow the&amp;nbsp; application adobe-update, java-update, kaspersky, ms-update with the service&amp;nbsp; type http/https&lt;BR /&gt;&lt;BR /&gt;I don't do any file level blocking in that&amp;nbsp; rule.&lt;BR /&gt;&lt;BR /&gt;Under the above updates rule I have my normal user based url filter&amp;nbsp; with http/https which contains the block to .exe types.&lt;BR /&gt;The application for&amp;nbsp; the user based filter is any.&lt;BR /&gt;&lt;BR /&gt;The Palo Alto is smart enough to be able to&amp;nbsp; decipher these update applications, and so far all is working&amp;nbsp; appropriately.&lt;BR /&gt;&lt;BR /&gt;Let me know if this helps..&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 15:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-microsoft-and-java-updates/m-p/32416#M23756</guid>
      <dc:creator>khaldeman</dc:creator>
      <dc:date>2011-09-23T15:39:24Z</dc:date>
    </item>
  </channel>
</rss>

