<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: You tube filtration issues in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71627#M40855</link>
    <description>&lt;P&gt;Do you decrypt traffic?&lt;/P&gt;
&lt;P&gt;You can test if user is in specific group with command below:&lt;/P&gt;
&lt;P&gt;show user user-ids match-user john&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can firewall identify that user is in the group you use in the policy?&lt;/P&gt;
&lt;P&gt;If you go to traffic log is traffic correctly identified (or it is just ssl)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For me youtube always redirects me to https version so how can you access it over http?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jan 2016 15:31:44 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2016-01-26T15:31:44Z</dc:date>
    <item>
      <title>You tube filtration issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71624#M40854</link>
      <description>&lt;P&gt;I'm at a bit of a losst and am writing to see if anyone else has experienced anything like this:&lt;/P&gt;
&lt;P&gt;I have a policy that allows unrestricted access to youtube.com via http/https.&amp;nbsp; Accessing this rule is only allowed based on membership in an AD group.&amp;nbsp; And in testing, it seems to work, when i add my user object to the policy itself. I don't access to AD to insert myself into various groups for testing.&lt;/P&gt;
&lt;P&gt;So here's where it gets wierd.&lt;/P&gt;
&lt;P&gt;I have some members in that group that are able to access it using https and not http, and for the life of me I can't figure out why.&lt;/P&gt;
&lt;P&gt;Anybody have anything like this happen before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thansk,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bws&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 14:56:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71624#M40854</guid>
      <dc:creator>bwsaloum</dc:creator>
      <dc:date>2016-01-26T14:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: You tube filtration issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71627#M40855</link>
      <description>&lt;P&gt;Do you decrypt traffic?&lt;/P&gt;
&lt;P&gt;You can test if user is in specific group with command below:&lt;/P&gt;
&lt;P&gt;show user user-ids match-user john&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can firewall identify that user is in the group you use in the policy?&lt;/P&gt;
&lt;P&gt;If you go to traffic log is traffic correctly identified (or it is just ssl)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For me youtube always redirects me to https version so how can you access it over http?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 15:31:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71627#M40855</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-01-26T15:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: You tube filtration issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71648#M40870</link>
      <description>&lt;P&gt;Raido, first of all, thank you for the reply.&amp;nbsp; My responses will be in blue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you decrypt traffic? &lt;FONT color="#3366ff"&gt;Yes, but not in this particular policy&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;You can test if user is in specific group with command below:&lt;/P&gt;
&lt;P&gt;show user user-ids match-user john &lt;FONT color="#3366ff"&gt;Executed like expected and sees all of the users in question being associated with that group. (I ran this command on a sample group of 10 users and the response was consistently the same)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can firewall identify that user is in the group you use in the policy? &lt;FONT color="#3366ff"&gt;Yes as there are other websites being processed by this policy and that all works properly.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;If you go to traffic log is traffic correctly identified (or it is just ssl)?&lt;FONT color="#3366ff"&gt; I see both 80 and 443 and other sites, seem to be processed properly.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#3366ff"&gt;I even went so far as to specify the user object in the policy, at the same level as the group, in the event that the firewalls weren't recognizing the group members. No joy. So I'm at a bit of a loss on this one.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For me youtube always redirects me to https version so how can you access it over http?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 17:12:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71648#M40870</guid>
      <dc:creator>bwsaloum</dc:creator>
      <dc:date>2016-01-26T17:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: You tube filtration issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71651#M40872</link>
      <description>&lt;P&gt;So expectation is to allow Youtube right?&lt;/P&gt;
&lt;P&gt;And it is not working?&lt;/P&gt;
&lt;P&gt;If you go to traffic log and filter based on used and search for sessions that were not permitted.&lt;/P&gt;
&lt;P&gt;(user.src.eq 'domain\user' ) and (action neq allow)&lt;/P&gt;
&lt;P&gt;Then you should see blocked sessions.&lt;/P&gt;
&lt;P&gt;Click on mag glass.&lt;/P&gt;
&lt;P&gt;What is session end reason?&lt;/P&gt;
&lt;P&gt;What is application identified?&lt;/P&gt;
&lt;P&gt;Against what rule this traffic matched?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By default only ended sessions show up in traffic log so you might want to check session table also or check "Log at Session Start" on policy during troubleshooting.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 17:24:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71651#M40872</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-01-26T17:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: You tube filtration issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71656#M40873</link>
      <description>&lt;P&gt;First off &lt;U&gt;&lt;STRONG&gt;THANK YOU&lt;/STRONG&gt;&lt;/U&gt;!&amp;nbsp; I believe I was getting caught up on a single tree in forest, so to speak... What was happening is elements of Youtube are being classified as google-base, and since that's not explicitly allowed, it's flagging the entire session.&amp;nbsp; Now that I know the cause &amp;amp; effect, I can work it out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again and cheers!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bws&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 19:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/you-tube-filtration-issues/m-p/71656#M40873</guid>
      <dc:creator>bwsaloum</dc:creator>
      <dc:date>2016-01-26T19:26:09Z</dc:date>
    </item>
  </channel>
</rss>

