<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow certain EXE downloads by filename in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42247#M31052</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;There are App-ID's for various software updates.&amp;nbsp; You can allow file downloads for those App-ID's.&amp;nbsp; If your particular malware update is not covered by an App-ID you can either create your own custom one or put in an App-ID request to Palo Alto Networks:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.paloaltonetworks.com/researchcenter/submit-an-application/"&gt;http://www.paloaltonetworks.com/researchcenter/submit-an-application/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jul 2011 20:58:40 GMT</pubDate>
    <dc:creator>kbrazil</dc:creator>
    <dc:date>2011-07-26T20:58:40Z</dc:date>
    <item>
      <title>Allow certain EXE downloads by filename</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42246#M31051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I use data filtering and currently block EXE downloads amoung others. My problem is now my users can't download updates to their malware software. The malware software we use currently doesn't offer a centralized management feature so the updates have to be downloaded from the web. The updates come from a content delivery network so the only way I can allow this without opening a huge hole in my security is by allowing a certain filename. Unfortuantely, I do not know of a way in my PA to allow an EXE downloads via filename while still blocking everything else. Is this possible? Thank you in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 20:30:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42246#M31051</guid>
      <dc:creator>ghight</dc:creator>
      <dc:date>2011-07-26T20:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Allow certain EXE downloads by filename</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42247#M31052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;There are App-ID's for various software updates.&amp;nbsp; You can allow file downloads for those App-ID's.&amp;nbsp; If your particular malware update is not covered by an App-ID you can either create your own custom one or put in an App-ID request to Palo Alto Networks:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.paloaltonetworks.com/researchcenter/submit-an-application/"&gt;http://www.paloaltonetworks.com/researchcenter/submit-an-application/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 20:58:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42247#M31052</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-07-26T20:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Allow certain EXE downloads by filename</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42248#M31053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you add a new "allow" policy using a FQDN Address Object for the content delivery network?&amp;nbsp; Do not add a file blocking profile to the new policy.&amp;nbsp; Position it before the policy with the file blocking profile that blocks .EXE files.&amp;nbsp; Traffic would then match the new policy and be allowed.&amp;nbsp; Downloads of .EXE files would still be blocked for traffic not sourced from the content delivery network by the existing policy with the file blocking profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 21:00:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42248#M31053</guid>
      <dc:creator>jdavis</dc:creator>
      <dc:date>2011-07-26T21:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Allow certain EXE downloads by filename</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42249#M31054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I could, and that was my first idea... but since a VAST majority of downloads come this content delivery network, I would essentially be allowing everything rendering my EXE blocking only minimally effective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll check in to Kelly's idea. I'm not familiar with that method, but it sounds like something I should know how to do anyway. Thank you both!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 21:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-certain-exe-downloads-by-filename/m-p/42249#M31054</guid>
      <dc:creator>ghight</dc:creator>
      <dc:date>2011-07-26T21:08:09Z</dc:date>
    </item>
  </channel>
</rss>

