<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Overcoming an application filter and url groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/overcoming-an-application-filter-and-url-groups/m-p/41683#M30667</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, I guess the bottom lien is tune, tune, tune.&amp;nbsp; It is a different way of thinking than a typical firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was also thinking of customizing the risk ratings on the apps down to a lower level, then filter all apps with "risk 5" but am not sure if the customized risk rating would be reset during a future update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Apr 2012 02:15:04 GMT</pubDate>
    <dc:creator>BobW</dc:creator>
    <dc:date>2012-04-19T02:15:04Z</dc:date>
    <item>
      <title>Overcoming an application filter and url groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overcoming-an-application-filter-and-url-groups/m-p/41681#M30665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This example is fictitious, but you will get the idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to use an application filter to block all "peer to peer".&amp;nbsp; So I create the necessary filter.&amp;nbsp; Then I determine that I want to allow one of the items which is defined in the "peer to peer" filter.&amp;nbsp; Is there some way to overcome/remove the app from the filter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope there is, otherwise I am afraid the filter process might not be very helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While we're at it...How about overcoming URL groups?&amp;nbsp; Example is I woudl like to allow some of the items in the social networking group but block all Chatroullette type sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2012 03:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overcoming-an-application-filter-and-url-groups/m-p/41681#M30665</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-04-18T03:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Overcoming an application filter and url groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overcoming-an-application-filter-and-url-groups/m-p/41682#M30666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The tricky part is when one object belongs to two groups or more at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would then recommend to use the following setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Blacklist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Whitelist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Default deny (+ log on session end).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if one URL belongs to both "malware sites" and "travel sites" at the same time (and malware is blacklisted and travel is whitelisted).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case I think you can solve your problem by doing this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Allow specific app.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Deny application-filter peer-to-peer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Other rules...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Default deny (+ log on session end).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tricky part is if the app you wish to allow also have a dependency to a much wider app such as web-browsing or unknown in case one of these is part of the applications you wish to block (or not allow).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2012 05:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overcoming-an-application-filter-and-url-groups/m-p/41682#M30666</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-04-18T05:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Overcoming an application filter and url groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overcoming-an-application-filter-and-url-groups/m-p/41683#M30667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, I guess the bottom lien is tune, tune, tune.&amp;nbsp; It is a different way of thinking than a typical firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was also thinking of customizing the risk ratings on the apps down to a lower level, then filter all apps with "risk 5" but am not sure if the customized risk rating would be reset during a future update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2012 02:15:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overcoming-an-application-filter-and-url-groups/m-p/41683#M30667</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-04-19T02:15:04Z</dc:date>
    </item>
  </channel>
</rss>

