<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block ms-update for GlobalProtect sessions? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68378#M39892</link>
    <description>&lt;P&gt;you could also use QoS to slow down the updates. So if no bandwith is used then the updates will load with max. bandwith (or a max. value konfigured by you), but if there is more important traffic the updates will be slowed down for example to only 1 mbit/s&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2015 15:25:56 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2015-11-19T15:25:56Z</dc:date>
    <item>
      <title>Block ms-update for GlobalProtect sessions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68374#M39889</link>
      <description>&lt;P&gt;Hi all --&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lately, with the Win10 release, I'm finding many of my VPN users are downloading gigs of updates over my meager 10mbps company&amp;nbsp;internet cxn. &amp;nbsp;I'm wondering if there is any way to&amp;nbsp;block specific services/applications (ie.- ms-update) over a GlobalProtect connection.. &amp;nbsp;I can't find anywhere to specify a URL filtering profile in the Gateway config.. Would I apply a profile to the VPN IP Pool in&amp;nbsp;the Security Policies? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;-- michael~&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;edit: &amp;nbsp;Running on PA200, wth PanOS 6.1.5.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 14:29:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68374#M39889</guid>
      <dc:creator>thatguy</dc:creator>
      <dc:date>2015-11-19T14:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block ms-update for GlobalProtect sessions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68375#M39890</link>
      <description>&lt;P&gt;Yep, that's exactly how you would do it. &amp;nbsp;Create a security policy that says:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;from GP Zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;to untrust&lt;/P&gt;
&lt;P&gt;&amp;nbsp;app ms-update&lt;/P&gt;
&lt;P&gt;&amp;nbsp;action block&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're terminating the GlobalProtect users in your "trust zone", then be more specific about the source like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; from trust zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp; from 192.168.1.20-192.168.1.29&lt;/P&gt;
&lt;P&gt;&amp;nbsp; to untrust&lt;/P&gt;
&lt;P&gt;&amp;nbsp; app ms-update&lt;/P&gt;
&lt;P&gt;&amp;nbsp; action block&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just make sure that you place this security policy above the policy that permits your GP users to get out to the Internet. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 14:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68375#M39890</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2015-11-19T14:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Block ms-update for GlobalProtect sessions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68376#M39891</link>
      <description>&lt;P&gt;much appreciated. thank you&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 14:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68376#M39891</guid>
      <dc:creator>thatguy</dc:creator>
      <dc:date>2015-11-19T14:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Block ms-update for GlobalProtect sessions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68378#M39892</link>
      <description>&lt;P&gt;you could also use QoS to slow down the updates. So if no bandwith is used then the updates will load with max. bandwith (or a max. value konfigured by you), but if there is more important traffic the updates will be slowed down for example to only 1 mbit/s&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 15:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ms-update-for-globalprotect-sessions/m-p/68378#M39892</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2015-11-19T15:25:56Z</dc:date>
    </item>
  </channel>
</rss>

