<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security rules when ISP is caching? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5678#M4157</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if i understanding your questions correctly. &lt;/P&gt;&lt;P&gt;However if you are trying to block certain type of traffic why would you do it in a traditional manner of blocking it based on IP. Rather you should be taking advantage of the AppID and block it based on the application name. &lt;BR /&gt;Doing this you will not have to worry about keeping track of what IP is cached and what IP you need to block. Hope this help in blocking the desired traffic. &lt;BR /&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Feb 2014 23:03:22 GMT</pubDate>
    <dc:creator>mbutt</dc:creator>
    <dc:date>2014-02-21T23:03:22Z</dc:date>
    <item>
      <title>Security rules when ISP is caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5677#M4156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In looking at outbound traffic I can see quite a bit to a network range owned by my ISP. I'm guessing that it's a cache. The application traffic seems to be what one would expect to be efficiently cached (ms-update, symantec-av-update, http-video, etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you write rules for that? Or is it that, say, Microsoft is taking an ms-update request and pointing the connection to the cache (based on my IP)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 17:35:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5677#M4156</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2014-02-19T17:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Security rules when ISP is caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5678#M4157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if i understanding your questions correctly. &lt;/P&gt;&lt;P&gt;However if you are trying to block certain type of traffic why would you do it in a traditional manner of blocking it based on IP. Rather you should be taking advantage of the AppID and block it based on the application name. &lt;BR /&gt;Doing this you will not have to worry about keeping track of what IP is cached and what IP you need to block. Hope this help in blocking the desired traffic. &lt;BR /&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 23:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5678#M4157</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-02-21T23:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security rules when ISP is caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5679#M4158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the point of view of security, you may have two types of rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are trusting the ip range because this is your selected ISP and you trust what they choose to source from this range.&amp;nbsp; Then write a traditional ip address based allow rule from your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are allowing the listed applications, then you create an application based allow rule to any ip address and permit the traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Feb 2014 15:58:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5679#M4158</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-02-22T15:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security rules when ISP is caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5680#M4159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd like to tightly secure the outbound traffic I'm talking about. I'd rather not use &lt;EM&gt;just&lt;/EM&gt; IP or &lt;EM&gt;just&lt;/EM&gt; Application. I'd like to use both. A sample use case:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some McAfee EPO traffic is being served from the cache. It is classified as web-browsing. I'd like to prevent general web browsing from that EPO server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Feb 2014 14:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5680#M4159</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2014-02-25T14:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security rules when ISP is caching?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5681#M4160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order to do that you will have to create a custom application.Below docs can shows two different ways you can do it&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;How to Create an Application Override Policy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2015"&gt;Custom Application Signatures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps you resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Feb 2014 21:00:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rules-when-isp-is-caching/m-p/5681#M4160</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-02-26T21:00:07Z</dc:date>
    </item>
  </channel>
</rss>

