<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dealing with Drop Box in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dealing-with-drop-box/m-p/47204#M34691</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just an update to the discussion thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dropbox is currently using a certificate which is not compatible with the PAN&amp;nbsp; firewall (the PAN firewall conforms highly to the SSL RFCs).&amp;nbsp; As a&amp;nbsp; result, Dropbox SSL traffic cannot be decrypted, and its file operations&amp;nbsp; cannot be detected.&amp;nbsp; Dropbox's certificate is&amp;nbsp; added to the ssl-decrypt exclude-cache list. &lt;BR /&gt; &lt;BR /&gt;The following is a KP article listing sites which we are unable to perform SSL decryption on, and Dropbox.com is one of them. &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1423"&gt;https://live.paloaltonetworks.com/docs/DOC-1423&lt;/A&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;In general, these sites cannot be decrypted because they deviate&amp;nbsp; from SSL encryption standards in one form or another (i.e. use&amp;nbsp; proprietary encryption, require a specific type of certificate, etc). &lt;BR /&gt; &lt;BR /&gt;The status of the Dropbox&amp;nbsp; SSL certificate can be verified by looking at the ssl-decrypt&amp;nbsp; exclude-cache file on the firewall using the following CLI command - it is shown as an unsupported cert: &lt;BR /&gt; &lt;BR /&gt;admin@PA-200&amp;gt; show system setting ssl-decrypt exclude-cache | match 199.47.216.171 &lt;BR /&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.47.216.171:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40874&amp;nbsp;&amp;nbsp; CERT_UNSUPPORTED&amp;nbsp;&amp;nbsp;&amp;nbsp; undecided &lt;BR /&gt; &lt;BR /&gt;In summary, currently dropbox can be allowed or denied, but cannot selectively allow downloads while blocking uploads.&amp;nbsp; This may change in the future if/when dropbox uses a compatible certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 May 2012 02:10:02 GMT</pubDate>
    <dc:creator>snowcrash</dc:creator>
    <dc:date>2012-05-02T02:10:02Z</dc:date>
    <item>
      <title>Dealing with Drop Box</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dealing-with-drop-box/m-p/47202#M34689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can some one help as we are new to this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to blook and application call Drop box, Our users use this application to pull data from external networks wich we want to allow but we want to block drop box sharing our data off our network. could some one help me do this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 15:16:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dealing-with-drop-box/m-p/47202#M34689</guid>
      <dc:creator>payntonm</dc:creator>
      <dc:date>2011-08-12T15:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dealing with Drop Box</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dealing-with-drop-box/m-p/47203#M34690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can identify dropbox as an app, and you have two options to control it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. deny all dropbox traffic by policy&lt;/P&gt;&lt;P&gt;2. allow dropbox, and use file blocking profile to deny file upload out of all of our supported file types (over 50 types now, including common office doc, common compressed file format such as zip and rar, and also encrypted compressed file format such as encrypted rar and zip) for dropbox.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Approch 2 should be more suitable to your scenario. Though 100% what you want to do, but should be very close.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Aug 2011 05:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dealing-with-drop-box/m-p/47203#M34690</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-13T05:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dealing with Drop Box</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dealing-with-drop-box/m-p/47204#M34691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just an update to the discussion thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dropbox is currently using a certificate which is not compatible with the PAN&amp;nbsp; firewall (the PAN firewall conforms highly to the SSL RFCs).&amp;nbsp; As a&amp;nbsp; result, Dropbox SSL traffic cannot be decrypted, and its file operations&amp;nbsp; cannot be detected.&amp;nbsp; Dropbox's certificate is&amp;nbsp; added to the ssl-decrypt exclude-cache list. &lt;BR /&gt; &lt;BR /&gt;The following is a KP article listing sites which we are unable to perform SSL decryption on, and Dropbox.com is one of them. &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1423"&gt;https://live.paloaltonetworks.com/docs/DOC-1423&lt;/A&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;In general, these sites cannot be decrypted because they deviate&amp;nbsp; from SSL encryption standards in one form or another (i.e. use&amp;nbsp; proprietary encryption, require a specific type of certificate, etc). &lt;BR /&gt; &lt;BR /&gt;The status of the Dropbox&amp;nbsp; SSL certificate can be verified by looking at the ssl-decrypt&amp;nbsp; exclude-cache file on the firewall using the following CLI command - it is shown as an unsupported cert: &lt;BR /&gt; &lt;BR /&gt;admin@PA-200&amp;gt; show system setting ssl-decrypt exclude-cache | match 199.47.216.171 &lt;BR /&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.47.216.171:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40874&amp;nbsp;&amp;nbsp; CERT_UNSUPPORTED&amp;nbsp;&amp;nbsp;&amp;nbsp; undecided &lt;BR /&gt; &lt;BR /&gt;In summary, currently dropbox can be allowed or denied, but cannot selectively allow downloads while blocking uploads.&amp;nbsp; This may change in the future if/when dropbox uses a compatible certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 02:10:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dealing-with-drop-box/m-p/47204#M34691</guid>
      <dc:creator>snowcrash</dc:creator>
      <dc:date>2012-05-02T02:10:02Z</dc:date>
    </item>
  </channel>
</rss>

