<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking Cloud-Based services in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-cloud-based-services/m-p/39770#M29164</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess your best option is to use whitelisting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is define which apps should be allowed or not. Apps which isnt allowed will be blocked by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And in some cases organize this in such way so you have a blacklist (for example url-based) before that allow rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that more and more online services are using the "cloud" in one way or another.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean I guess you will allow access to gmail and when you do this the user can use various plugins in their browsers to use gmail as a datastorage which brings you a tricky situation of defining what is a cloud service and what isnt.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Jun 2013 05:53:01 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-06-14T05:53:01Z</dc:date>
    <item>
      <title>Blocking Cloud-Based services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-cloud-based-services/m-p/39769#M29163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for some practical experience on how to best block as many cloud-based services as possible.&lt;/P&gt;&lt;P&gt;I know I can probably create some Dynamic Filters for some apps, but other may need to be controlled differently (SSL decryption, block the domain name, etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering what the bulk of firewall admin or others are doing in such circumstances.&lt;/P&gt;&lt;P&gt;I am about to do a remote install, and I want to make sure I cover all my bases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 02:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-cloud-based-services/m-p/39769#M29163</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-06-14T02:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Cloud-Based services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-cloud-based-services/m-p/39770#M29164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess your best option is to use whitelisting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is define which apps should be allowed or not. Apps which isnt allowed will be blocked by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And in some cases organize this in such way so you have a blacklist (for example url-based) before that allow rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that more and more online services are using the "cloud" in one way or another.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean I guess you will allow access to gmail and when you do this the user can use various plugins in their browsers to use gmail as a datastorage which brings you a tricky situation of defining what is a cloud service and what isnt.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 05:53:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-cloud-based-services/m-p/39770#M29164</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-06-14T05:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Cloud-Based services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-cloud-based-services/m-p/39771#M29165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think what you are asking would be unbelievably cumbersome. As mikand said, you would have to to set this up as an extremely complex&amp;nbsp; whitelisting or have an extraordinarily long blacklist, or a combination thereof. Since all of these cloud based apps are based on the parent "web-browsing" and "ssl" and NGF policies are fundamentally based upon apps, you would have to come up with a list of apps that you truly want to block, and allow everything else (whitelist), or block them all (blacklist). There is an untold number of cloud services available with a plethora of use cases. I think what you really need to do is figure out what you don't want your users to be able to do (what is your business case), and then go from there. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 14:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-cloud-based-services/m-p/39771#M29165</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-06-14T14:20:57Z</dc:date>
    </item>
  </channel>
</rss>

