<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Selective Access to Facebook and Twitter in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46254#M33992</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think is more easy to configure that with security police rule with aplications.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;SO First create a policy allowing who you want have acess to facebook and twitter , etc....&lt;/P&gt;&lt;P&gt;After create other policy bottow of this policy denied everyone to application facebook and twitter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use URL filter , users can use other sites that connect to facebook with other URL like ebuddy.com.br&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thiago Lima.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jun 2012 20:11:19 GMT</pubDate>
    <dc:creator>Thiago</dc:creator>
    <dc:date>2012-06-28T20:11:19Z</dc:date>
    <item>
      <title>Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46250#M33988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;What's the best way to configure selective access to Facebook and Twitter (where some users have full access, while everyone else has no access).&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;The sources will be identified by IP address for right now (usernames later when I get to that).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;So far, all my attempts using combinations of App-ID and URL Filtering Profiles have failed.&amp;nbsp; I think the main thing that is giving me grief right now are the dependencies required for the App-IDs.&amp;nbsp; The Facebook and Twitter App-IDs also need the "Web-Browsing" App-ID to be allow through, but this ends up giving the selected users too much access (because their web-browsing hits this rule instead of the main "Allow Web-Browsing Out" rule further down the list that contains the URL Filtering Profile).&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;I need to have the URL Filtering Profiles on the "Allow Web-Browsing Out" rule to block access to other social networking sites and other URL categories.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;I've beening hitting my head against this brick wall for long enough....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;Thanks in advance for the help.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 22:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46250#M33988</guid>
      <dc:creator>PSC_IT</dc:creator>
      <dc:date>2012-06-26T22:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46251#M33989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should work for you.&lt;/P&gt;&lt;P&gt;1) Create a custom URL category that includes facebook and twitter URLS.&lt;/P&gt;&lt;P&gt;So you can create the category to include the following URLS "*.facebook.com/*" and "*.twitter.com/*&lt;/P&gt;&lt;P&gt;2)In the security policy select the following options.&lt;/P&gt;&lt;P&gt;application- web-browsing,facebook-base &amp;amp; twitter&lt;/P&gt;&lt;P&gt;service/URL category- add the custom URL category that you have created in step 1.&lt;/P&gt;&lt;P&gt;This should allow only facebook and twitter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 23:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46251#M33989</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-06-26T23:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46252#M33990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I got it (finally) working.&amp;nbsp; I'll have to do more testing to confirm that it does what I want without allowing something I don't want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a screenshot of the firewall rules:&lt;/P&gt;&lt;P&gt;&lt;IMG silly="" /&gt;&lt;/P&gt;&lt;P&gt;I separated the rules into two parts.&amp;nbsp; My thinking was that this way the rule "Twitter and Facebook 2" will only match traffic that is web-browsing AND fits the custom URL category I configured--nothing else.&amp;nbsp; Also, another reason is that Facebook and Twitter pulls dynamic page contents from multiple URLs, which have different URLs (and URL categories)--all of which will automatically be allowed by the "Twitter and Facebook 1" rule because the only URLs (and URL categories) that will match that rule will have an App-ID of facebook or twitter, which is what I want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, here's a screenshot of the custom URL category.&amp;nbsp; Some of the URLs maybe redundant and were added as I was initially testing this solution.&amp;nbsp; I'll have to test some more to see what is needed and delete the extras.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA Facebook and Twitter Rule 1a.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3141_PA Facebook and Twitter Rule 1a.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that helps anyone else who is trying to do the same thing I am.......keeping in mind I'm still testing this solution &lt;SPAN __jive_emoticon_name="_silly.gif'"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And thanks again to sdurga for pointing me in the right direction.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 16:14:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46252#M33990</guid>
      <dc:creator>PSC_IT</dc:creator>
      <dc:date>2012-06-28T16:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46253#M33991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are the *.ak.fbcdn.net, s-static.ak.fbcdn.net and s-static.ak.facebook.com really needed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean doesnt *.facebook.com and *.fbcdn.net already cover these?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 18:41:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46253#M33991</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-28T18:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46254#M33992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think is more easy to configure that with security police rule with aplications.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;SO First create a policy allowing who you want have acess to facebook and twitter , etc....&lt;/P&gt;&lt;P&gt;After create other policy bottow of this policy denied everyone to application facebook and twitter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use URL filter , users can use other sites that connect to facebook with other URL like ebuddy.com.br&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thiago Lima.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 20:11:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46254#M33992</guid>
      <dc:creator>Thiago</dc:creator>
      <dc:date>2012-06-28T20:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46255#M33993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I was working on this earlier, I tried many different things and combinations of things, including adding more and more URLs to see if that helped or not.&amp;nbsp; When I got things working, I did not go back and clean up the URLs I added (yet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyways, after some more trial and error (mostly error), here's the "clean" version of the custom URL category.&amp;nbsp; Note that I removed the &lt;EM&gt;&lt;STRONG&gt;/*&lt;/STRONG&gt; wildcard from the end of each URL--it seems to make everything work better.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA Facebook and Twitter Rule 1a Version 2.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3145_PA Facebook and Twitter Rule 1a Version 2.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.&amp;nbsp; I forgot to mention that the Facebook App-ID complained about a dependency call "jabber" needed for Facebook-chat.&amp;nbsp; I don't really care about the chat function in Facebook, so I probably won't put much effort in resolving this issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 20:12:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46255#M33993</guid>
      <dc:creator>PSC_IT</dc:creator>
      <dc:date>2012-06-28T20:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46256#M33994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi My friend!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont use url list to block facebook and twitter.&lt;/P&gt;&lt;P&gt;Use in application ! will solve your problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 20:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46256#M33994</guid>
      <dc:creator>Thiago</dc:creator>
      <dc:date>2012-06-28T20:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46257#M33995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thaigo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact, that's what I tried at first.&amp;nbsp; My very first attempt I had four rules, in the following order:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Allow:&amp;nbsp; Source: (My PC); Destination: (Any); App-ID: (facebook, twitter); URL-category: (Any)&lt;/LI&gt;&lt;LI&gt;Deny:&amp;nbsp; Source: (Any); Destination: (Any); App-ID: (facebook, twitter); URL-category: (Any)&lt;/LI&gt;&lt;LI&gt;All Web-browsing:&amp;nbsp; Source: (Any); Destination: (Any); App-ID: (web-browsing, SSL); URL-category: (Any)&amp;nbsp; Profile: (URL Filter profile blocking "Social networking" category)&lt;/LI&gt;&lt;LI&gt;Deny all:&amp;nbsp; Source: (Any); Destination: (Any); App-ID (Any); URL-category: (Any)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that before Facebook or Twitter (or many other applications) can be identified, they start out as basic "SSL" (for Facebook, "web-browsing" for Twitter) and as additional traffic is received, the Palo Alto gets enough traffic to identify the application traffic as Facebook or Twitter or whatever.&amp;nbsp; So, the inital traffic (i.e. the first packet of the TCP connection) is classified with a "SSL" App-ID and hits rule #3, which has the URL filtering blocking social networking.&amp;nbsp; Rule #3 will then block the inital Facebook/Twitter traffic, killing the connection before any further traffic is identified as Facebook/Twitter--Rules #2 and Rule #3 are never used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My original issue was that the Facebook and Twitter App-IDs needed "web-browsing" and "ssl" App-IDs to work, but adding those two dependent App-IDs would have allowed too much access for the selected Facebook and Twitter users.&amp;nbsp; But adding the basic URL filter profile to restrict access would have stopped the Facebook and Twitter App-IDs from working.&amp;nbsp; A little bit of a Catch-22 right there.&amp;nbsp; The custom URL category allows me to have a second "web-browsing" and "ssl" rule that only applies to the specific users I am allowing access to Facebook and Twitter.&amp;nbsp; Everyone else would hit the main "web-browsing" rule near the bottom of the policy list.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 20:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46257#M33995</guid>
      <dc:creator>PSC_IT</dc:creator>
      <dc:date>2012-06-28T20:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46258#M33996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thaigo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm &lt;SPAN style="text-decoration: underline;"&gt;not&lt;/SPAN&gt; using URL filtering to block Facebook and Twitter, I'm using the Facebook and Twitter App-IDs to allow specific people through.&amp;nbsp; Everyone else hits the Deny All rule at the bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The URL filter is &lt;SPAN style="text-decoration: underline;"&gt;only&lt;/SPAN&gt; for the web-browsing and SSL &lt;SPAN style="text-decoration: underline;"&gt;dependencies&lt;/SPAN&gt; required for the Facebook and Twitter App-ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 20:49:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46258#M33996</guid>
      <dc:creator>PSC_IT</dc:creator>
      <dc:date>2012-06-28T20:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46259#M33997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Instead of allowing facebook (which currently includes: facebook-mail, facebook-chat, facebook-social-plugin, facebook-base, facebook-apps, facebook-posting, facebook-file-sharing&amp;nbsp;&amp;nbsp; - check &lt;A href="http://apps.paloaltonetworks.com/applipedia/" title="http://apps.paloaltonetworks.com/applipedia/"&gt; Application Research Center&lt;/A&gt; for more info) you could just allow facebook-base (and perhaps facebook-posting).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 21:25:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46259#M33997</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-28T21:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46260#M33998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's very true if you want to allow limited access to Facebook/Twitter (i.e. look, but don't post), but in my case, if the selected person is allowed access to Facebook/Twitter, they are given full access to the site (except for whatever doesn't work because I don't feel like fixing it--like the "Jabber" App-ID needed for facebook-chat &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If our agency's Internet usage policy were to change, I could very easily change from the Facebook App-ID to more specific App-IDs, such as Facebook-base, Facebook-post, etc....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 21:34:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46260#M33998</guid>
      <dc:creator>PSC_IT</dc:creator>
      <dc:date>2012-06-28T21:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46261#M33999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IMHO you should not allow facebook-apps (unless you really know what you do &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 21:50:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46261#M33999</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-28T21:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Access to Facebook and Twitter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46262#M34000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;True, I forgot about that part of Facebook....something for me to modify tomorrow :smileymischief:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 21:53:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/selective-access-to-facebook-and-twitter/m-p/46262#M34000</guid>
      <dc:creator>PSC_IT</dc:creator>
      <dc:date>2012-06-28T21:53:10Z</dc:date>
    </item>
  </channel>
</rss>

