<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to block skype for 'trust' zone and allow for 'trust2' zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/431#M334</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does the traffic log show? Is everything showing up as Skype-base? Are you using a merged Skype/Live messenger account to test? The Skype program will use both the Live Messenger application and Skype-base application for chat if it is a merged account.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Feb 2013 21:53:32 GMT</pubDate>
    <dc:creator>SCoupland</dc:creator>
    <dc:date>2013-02-07T21:53:32Z</dc:date>
    <item>
      <title>how to block skype for 'trust' zone and allow for 'trust2' zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/428#M331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to block skype for one group of users (whitch are in 'l3-trust' security zone) and allow for second group (which are in 'l3-trust2' security zone).&lt;/P&gt;&lt;P&gt;Both zones: 'l3-trust' and 'l3-trust2' are source-NATed to 'l3-untrust' zone, one interface, one IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made policy rule allowing skype-probe from 'any' zone to 'any' zone and second policy which blocked skype from 'l3-trust' zone to 'l3-untrust'.&lt;/P&gt;&lt;P&gt;Unfortunately all users (from both trusted security zones) have access to skype.&lt;/P&gt;&lt;P&gt;Even, when I modify second rule and add also 'l3-trust2' to blocked zone for skype, skype is working for everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect some network misconfiguration, so I attach configuration screens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 14:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/428#M331</guid>
      <dc:creator>mariusz_sawczuk</dc:creator>
      <dc:date>2013-02-06T14:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: how to block skype for 'trust' zone and allow for 'trust2' zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/429#M332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The configuration looks OK. Can you please run the following commands.&amp;nbsp; R u trying to test this with SKYPE Test call ? because Skype test call works even you block skype &lt;A __default_attr="1505" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to make a skype call ( not the test call ) to one of the contacts from l3-trust zone and now look at the sessions information you do this via " show session info"&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1100" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;. Now from the sessions look wether the l3-trust users are hitting the correct security rule or not. Also in the sessions, look for what is the application. You should not see any thing other than Skype-probe or Skype. If application and the security rules are correct I do not see any reason for this to fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx,&lt;BR /&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 17:50:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/429#M332</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2013-02-06T17:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: how to block skype for 'trust' zone and allow for 'trust2' zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/430#M333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Voice calls are blocked, but chat is still possible. Wold be much more efficient just to completly block user login to skype. Is it possible in general, and if not how to disable chating in skype?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 23:41:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/430#M333</guid>
      <dc:creator>mariusz_sawczuk</dc:creator>
      <dc:date>2013-02-06T23:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: how to block skype for 'trust' zone and allow for 'trust2' zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/431#M334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does the traffic log show? Is everything showing up as Skype-base? Are you using a merged Skype/Live messenger account to test? The Skype program will use both the Live Messenger application and Skype-base application for chat if it is a merged account.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 21:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/431#M334</guid>
      <dc:creator>SCoupland</dc:creator>
      <dc:date>2013-02-07T21:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: how to block skype for 'trust' zone and allow for 'trust2' zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/432#M335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In report of 'show session all' I see that PAN recognize skype (even skype IM) as a 'skype' application and there is also skype-probe of course.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I didn;t told you about important thing, and I'm wondering now that is so matter in my case?&lt;/P&gt;&lt;P&gt;All my tests I'm doing on my laptop where I have Windows 7 installed, and it hosts virtual enviroment (VMWare Workstation) in whch I have virtual PAN and virtual Windows XP machine installed. &lt;/P&gt;&lt;P&gt;All traffic from virtual Windows XP is going through virtual PAN (secured, NATed and routed by virtual PAN), after that NATed to my physical interface (by VMware network mechanism) and after that routed to Internet..From the virtual Windows XP perspective, my Windows 7 host OS (and let say Internet) is in untrust zone. &lt;/P&gt;&lt;P&gt;I'm wondering now that could cause some impact for skype?&lt;/P&gt;&lt;P&gt;I observe that when I completelty block every traffic/applicaiton on virtual PAN, and when I launch Skype on virtual Windows XP it doesn't work. But when I'm launch Skype on my Windows 7 host OS&amp;nbsp; and restart Skype on virtual Windows XP it's start wokring and I can do call from Windows XP to Windows7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, as I mentioned both machines are zone based secured, but to be honest they have 'shared' network interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Virtual Palo Alto has 3 interfaces:&lt;/P&gt;&lt;P&gt;- untrust which is VMnet8 (NATed by VMWare interface)&lt;/P&gt;&lt;P&gt;- trust which is VMnet1 (host-only, isolated interface)&lt;/P&gt;&lt;P&gt;- trust2 which is VMnet2 (host-only, isolated interrface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Virutal Windows XP has only one interface which is in trust zone and it is VMNet1 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Host OS - Windows 7 of course sees alle above interfaces: VMnet8, VMnet1 and VMnet2, becuase it runs VMWare Workstaiton, which creates all this interfeaces.&lt;/P&gt;&lt;P&gt;So maybe skype could use it in some magic way nad this cause me problem?&lt;/P&gt;&lt;P&gt;If yes how to fix it and block skype?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 01:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-skype-for-trust-zone-and-allow-for-trust2-zone/m-p/432#M335</guid>
      <dc:creator>mariusz_sawczuk</dc:creator>
      <dc:date>2013-02-13T01:34:06Z</dc:date>
    </item>
  </channel>
</rss>

