<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking files by URL Category and Zone direction in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-files-by-url-category-and-zone-direction/m-p/49539#M36499</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears my resolution was that in my file blocking profile only had "download" for the direction.&amp;nbsp; Modifying to "both" looks to have done the trick. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Apr 2013 13:21:01 GMT</pubDate>
    <dc:creator>MGoodnow</dc:creator>
    <dc:date>2013-04-08T13:21:01Z</dc:date>
    <item>
      <title>Blocking files by URL Category and Zone direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-files-by-url-category-and-zone-direction/m-p/49537#M36497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I currently have a security rule that blocks the downloads of ".exe" files from the "unknown" URL category (which sits above my general Internet/WildFire Forward rule).&amp;nbsp; It works extremely well in dropping a huge amount of the garbage out there.&amp;nbsp; However, occasionally the garbage makes it past that rule and sends up a WildFire event.&amp;nbsp; Again, Deny rule comes before the WildFire forward.&amp;nbsp; I noticed from the WildFire alert that in the cases of communication which appears to bypass the deny rule - the source and destination are actually reversed to what the rule is set.&amp;nbsp; Instead of my user being the source - it is now the destination.&amp;nbsp; Should my rule to deny the .exe also include a bidirectional zone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current Deny .exe rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source Zone - Internal&lt;/P&gt;&lt;P&gt;Destination Zone - External &lt;/P&gt;&lt;P&gt;Application - Web-Browsing&lt;/P&gt;&lt;P&gt;URL Category - "Unknown" (PANDB)&lt;/P&gt;&lt;P&gt;Profile - "DenyEXE" File blocking profile for .exe/download/block&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should my zones be a bidirectional setup to block anything that is coming inbound? &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I had hoped the user session would keep state of that? &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Should the File Blocking profile be both upload and download?&amp;nbsp;&amp;nbsp; Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 20:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-files-by-url-category-and-zone-direction/m-p/49537#M36497</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2013-03-18T20:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking files by URL Category and Zone direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-files-by-url-category-and-zone-direction/m-p/49538#M36498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Want to add that if adding the bidirectional zone would be beneficial - it concerns me to add "external" source to "internal" destination in this case.&amp;nbsp; How big a concern is that in this particular setup? We are NAT'd behind the external interface.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 13:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-files-by-url-category-and-zone-direction/m-p/49538#M36498</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2013-03-19T13:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking files by URL Category and Zone direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-files-by-url-category-and-zone-direction/m-p/49539#M36499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears my resolution was that in my file blocking profile only had "download" for the direction.&amp;nbsp; Modifying to "both" looks to have done the trick. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Apr 2013 13:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-files-by-url-category-and-zone-direction/m-p/49539#M36499</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2013-04-08T13:21:01Z</dc:date>
    </item>
  </channel>
</rss>

