<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Chrome Updater not working if EXE is blocked / application not recognized in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39261#M28804</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) You posted in wrong subforum - hopefully someone from PA could move your thread so more people will notice it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) You can request app enhancement from the Apps and Threats Research Center.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.paloaltonetworks.com/researchcenter/tools/"&gt;http://www.paloaltonetworks.com/researchcenter/tools/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From there you can click on Submit an app and provide details there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) As workaround I think you can do an "application override" if you have something to trigger at. Like:&lt;/P&gt;&lt;P&gt;dsturl: update.google.com&lt;/P&gt;&lt;P&gt;appid: web-browsing&lt;/P&gt;&lt;P&gt;file: .exe&lt;/P&gt;&lt;P&gt;new appid: google-update&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Jul 2012 18:11:46 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-07-02T18:11:46Z</dc:date>
    <item>
      <title>Chrome Updater not working if EXE is blocked / application not recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39260#M28803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in one customer setup we face the following problem: We disabled EXE file downloading. In order do allow services to update we use an application filter with subcategory update and allow that traffic. Works like a charm for google-update, ms-update etc. However today I noticed tons of blocks from xxxxxx_Chrome_updater.exe (xxxxx being date, version etc.). The application is "web-browsing". So the update process is not discovered as being an update application. Is this an error or missing feature in the app-id? How can I whitelist this or make a custom application out of this? We see this more often with special EXEs we need to whitelist. Any idea of how to achieve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp; JP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 16:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39260#M28803</guid>
      <dc:creator>j.koopmann</dc:creator>
      <dc:date>2012-07-02T16:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Chrome Updater not working if EXE is blocked / application not recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39261#M28804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) You posted in wrong subforum - hopefully someone from PA could move your thread so more people will notice it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) You can request app enhancement from the Apps and Threats Research Center.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.paloaltonetworks.com/researchcenter/tools/"&gt;http://www.paloaltonetworks.com/researchcenter/tools/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From there you can click on Submit an app and provide details there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) As workaround I think you can do an "application override" if you have something to trigger at. Like:&lt;/P&gt;&lt;P&gt;dsturl: update.google.com&lt;/P&gt;&lt;P&gt;appid: web-browsing&lt;/P&gt;&lt;P&gt;file: .exe&lt;/P&gt;&lt;P&gt;new appid: google-update&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 18:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39261#M28804</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-02T18:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Chrome Updater not working if EXE is blocked / application not recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39262#M28805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ad 1) sorry. which one would have been more suitable? Still have to find my way around Jive I suppose...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ad 2) Done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ad 3) This is more or less exactly what I want. But I fail to see where/how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dsturl: update.google.com does not exist. I am trying to figure out which one is the correct URL. I started a pcap and hope that the next request will show the necessary information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how do you configure this sort of application override? The ones I know are based on source/destination IP/port not application/file etc. I could create a new application which is based on signatures but how? Where to put the url (request uri?) and how to match on the filename (I would need a regex for that if regex is supported).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp; JP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 19:50:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39262#M28805</guid>
      <dc:creator>j.koopmann</dc:creator>
      <dc:date>2012-07-02T19:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Chrome Updater not working if EXE is blocked / application not recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39263#M28806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) Click on Home in the upper left then on KnowledgePoint and finally Discussion &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Oops sorry... application override doesnt act on url. However you can go for dstip (which I guess wont work in this case since its Google we speak about and too many ip's).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Custom application would then be the way to go...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think something like this might help you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parent-app: web-browsing&lt;/P&gt;&lt;P&gt;defaults port: tcp/443 (assuming its using https only)&lt;/P&gt;&lt;P&gt;ip protocol: 6 (tcp)&lt;/P&gt;&lt;P&gt;scanning: file-types, data-patterns, viruses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then the actual signature... check page 171 in the admin guide for examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since this is mainly to allow traffic I think you should be as narrow as you possible can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont forget to have ssl-termination running in order to inspect the https contents.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 20:24:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/chrome-updater-not-working-if-exe-is-blocked-application-not/m-p/39263#M28806</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-02T20:24:28Z</dc:date>
    </item>
  </channel>
</rss>

