<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to block malware coming over VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-coming-over-vpn/m-p/63364#M38143</link>
    <description>&lt;P&gt;Last week we had an internal user that was infected with CryptoLocker. Our users get through GPO network drives and also some of the files on these drivers were infected. We could disinfect the system and the files and we generated a GPO so no malware can be run from %appdata% and we also did some other changes. The only thing I'm afraid about is when external users login with there personal laptop (that is infected)&amp;nbsp;to the VPN and they map a network drive, a virus can be spread out. We can't deploy GPO to an external user his/her laptop. What is the best solution?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2015 06:24:15 GMT</pubDate>
    <dc:creator>ZEBIT</dc:creator>
    <dc:date>2015-08-20T06:24:15Z</dc:date>
    <item>
      <title>How to block malware coming over VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-coming-over-vpn/m-p/63364#M38143</link>
      <description>&lt;P&gt;Last week we had an internal user that was infected with CryptoLocker. Our users get through GPO network drives and also some of the files on these drivers were infected. We could disinfect the system and the files and we generated a GPO so no malware can be run from %appdata% and we also did some other changes. The only thing I'm afraid about is when external users login with there personal laptop (that is infected)&amp;nbsp;to the VPN and they map a network drive, a virus can be spread out. We can't deploy GPO to an external user his/her laptop. What is the best solution?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 06:24:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-coming-over-vpn/m-p/63364#M38143</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2015-08-20T06:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to block malware coming over VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-coming-over-vpn/m-p/63375#M38147</link>
      <description>&lt;P&gt;Hello Zebit,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;one of the ways you can handle this is to enforce HIP checks on their devices and ensure that they have latest antivirus updates, OS updates, etc. By using HIP you can separate users or deny them access to sensitive network areas until they improve their security posture, whatever your criteria was.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regardless of HIP checks, your VPN/GP users will be arriving to a separate network pool. It is easy and practical to put them in their own separate zone, and than apply rules for communication between different zones as you would with any other traffic. Just create a policy for access from the VPN zone towards the DMZ (or wherever your servers are) and apply anti-virus and other security profiles onto the given policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are a few documents that might give you more information on this topic all in all, if you need them: &lt;A href="https://live.paloaltonetworks.com/t5/Articles/Security-Policy-Quick-Reference-Resource-List/ta-p/54619" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Articles/Security-Policy-Quick-Reference-Resource-List/ta-p/54619&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you need more info, just ask here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 08:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-coming-over-vpn/m-p/63375#M38147</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-20T08:28:19Z</dc:date>
    </item>
  </channel>
</rss>

