<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking EXE files but allowing file names in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93040#M43762</link>
    <description>&lt;P&gt;You have to have 2 seperate security policies and 2 seperate File Blocking profiles.&lt;/P&gt;&lt;P&gt;Top sec policy will allow download of executables and you have URL category attached to it.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2016 13:31:49 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2016-06-28T13:31:49Z</dc:date>
    <item>
      <title>Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/92546#M43724</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to block .exe files, but allow file names for some users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I would like to allow the GoToMeetingLauncher.exe for GoToMeeting webinars, but the links look like the below which means it can't be done.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://download.citrixonline.com/launcher2/helper?token=e0-qZ0xbknQkdODLP_tA0HpRDCszfG5OkCLe4-4_8LabqVRaLatg9Q4O519wF6GlqPnLvKAVHZz9kXX346UVgmp5gTJaxWPhQZgKI-VAp8hlZX6-AQjQkiwjOQMFgW9z0-9JRcDHvBx31IUAD3a5RPg4vZWzqgmTyt4wN3Q-noL5JMG0ROJk--2QVj_ACF044_X8yv9lbRd8kPJC58Gq0jWtCzE-DLtGHU1xZioBDd6IWLyOm3FbllUjg9Aw4v93px8maTbbN5Y2DuYkSoXE0Mshf85BwSxvxNMP8Pdu5Kq0jzU01CKvkzBs69l8Ux53V9MWLFa7fqWrbyRwh7fjTHl7TXTi4gKqaPZmlL8AM9OD6QA0e18jX1tqH1Ycl2kRVHLIM2GCrTTSRmr60i3cY34dXx82DTk3FHB5NIx4dobWpvepQLFOWbdeO6v_CTeXBtYB1VNiVY1mwT9UhzCt-DE0nSOYGJA7M75AMlIstRfTxmpB-xR&amp;amp;downloadTrigger=restart&amp;amp;renameFile=1" target="_blank"&gt;https://download.citrixonline.com/launcher2/helper?token=e0-qZ0xbknQkdODLP_tA0HpRDCszfG5OkCLe4-4_8LabqVRaLatg9Q4O519wF6GlqPnLvKAVHZz9kXX346UVgmp5gTJaxWPhQZgKI-VAp8hlZX6-AQjQkiwjOQMFgW9z0-9JRcDHvBx31IUAD3a5RPg4vZWzqgmTyt4wN3Q-noL5JMG0ROJk--2QVj_ACF044_X8yv9lbRd8kPJC58Gq0jWtCzE-DLtGHU1xZioBDd6IWLyOm3FbllUjg9Aw4v93px8maTbbN5Y2DuYkSoXE0Mshf85BwSxvxNMP8Pdu5Kq0jzU01CKvkzBs69l8Ux53V9MWLFa7fqWrbyRwh7fjTHl7TXTi4gKqaPZmlL8AM9OD6QA0e18jX1tqH1Ycl2kRVHLIM2GCrTTSRmr60i3cY34dXx82DTk3FHB5NIx4dobWpvepQLFOWbdeO6v_CTeXBtYB1VNiVY1mwT9UhzCt-DE0nSOYGJA7M75AMlIstRfTxmpB-xR&amp;amp;downloadTrigger=restart&amp;amp;renameFile=1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Can-Files-be-Blocked-by-Name/ta-p/54157" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Can-Files-be-Blocked-by-Name/ta-p/54157&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyone have an insight as to what they have done before, or what could be done?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jack&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2016 16:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/92546#M43724</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-27T16:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/92560#M43725</link>
      <description>&lt;P&gt;Create custom URL category.&lt;/P&gt;&lt;P&gt;Add&amp;nbsp;download.citrixonline.com into it.&lt;/P&gt;&lt;P&gt;Allow download of executables (for specific users) from that URL category.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2016 16:31:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/92560#M43725</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-27T16:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93039#M43761</link>
      <description>&lt;P&gt;Hi Raido,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hmm,&amp;nbsp;thanks for your response but this didn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created the custom category and set it to Alert for the policy that applies to me but when I tri the download again this is still being blocked. It doesn’t seem to override the file block policy. Is there a different way of doing this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Jack&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 13:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93039#M43761</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-28T13:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93040#M43762</link>
      <description>&lt;P&gt;You have to have 2 seperate security policies and 2 seperate File Blocking profiles.&lt;/P&gt;&lt;P&gt;Top sec policy will allow download of executables and you have URL category attached to it.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 13:31:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93040#M43762</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-28T13:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93323#M43808</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can go to the website and download the launcher fine, it’s other websites that I can’t access anymore (because I set all other categories to Block). In my mind I’m expecting to hit the top policy for downloads only (hence blocking everything else) then hit the regular policy below for all other traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 12:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93323#M43808</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-29T12:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93327#M43812</link>
      <description>&lt;P&gt;Palo is a "top down ACL" so if you're using all the same parameters except just chaning a profile the rules below the one above should be shadowed and not hit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you committed did you get a "shadowed rule" warning message?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 14:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93327#M43812</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-06-29T14:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93331#M43815</link>
      <description>&lt;P&gt;Yeah so essentially, the match conditions are the same, so the traffic will hit the first rule that it applies to regardless of what file blocking profile you have.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any workaround for this at all? Would it be possible to setup an Untrust to Trust policy from the web server of where you're downloading from, which then has an alternate file blocking profile to allow this specific traffic I'm trying to download an EXE of?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 15:02:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93331#M43815</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-29T15:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93332#M43816</link>
      <description>&lt;P&gt;The work around is a roll-up or integration of all match conditions and desired accesses/restirctions for the desired user security group.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 15:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93332#M43816</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-06-29T15:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93333#M43817</link>
      <description>&lt;P&gt;Could you decipher that please..&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 15:35:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93333#M43817</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-29T15:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93347#M43823</link>
      <description>&lt;P&gt;For the sake of arguement:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trust --&amp;gt; Any IP --&amp;gt; Security Group A --&amp;gt; UnTrust --&amp;gt; Any IP --&amp;gt; Application Web-Browsing --&amp;gt; Application-Default --&amp;gt; Any URL Category &amp;nbsp;--&amp;gt; Allow &amp;nbsp;--&amp;gt; URL Profile A &amp;nbsp;(Block Everything) / File Blocking Profile (Can transfer .pdfs only)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Trust --&amp;gt; Any IP --&amp;gt; Security Group A --&amp;gt; UnTrust --&amp;gt; Any IP --&amp;gt; Application Web-Browsing --&amp;gt; Application-Default --&amp;gt; Any URL Category &amp;nbsp;--&amp;gt; Allow &amp;nbsp;--&amp;gt; URL Profile A &amp;nbsp;(Allow Everything) / File Blocking Profile (Can transfer .pdfs only)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Rule 1 will shadow rule 2 because it's the same base session match criteria. &amp;nbsp;The application web-browsing will be allowed but the palo doesn't know which rule should "hit" WRT your URL match criteria.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Really the easiest way to do what you want is to do as Raido said.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. &amp;nbsp;Create a Custom URL category (Call it whatever "Meeting") --&amp;gt; Add the URL&amp;nbsp;download.citrixonline.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. &amp;nbsp;Create a File Blocking Profile ("EXE Allow") --&amp;gt; Allow exe files to download&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. &amp;nbsp;Create Rule&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Trust --&amp;gt; Any IP --&amp;gt; Security Group A --&amp;gt; UnTrust --&amp;gt; Any IP --&amp;gt; Application Web-Browsing --&amp;gt; Application-Default --&amp;gt; "Meeting"&amp;nbsp; --&amp;gt; Allow &amp;nbsp;--&amp;gt; NO URL PROFILE&amp;nbsp;/ File Blocking Profile&amp;nbsp;"EXE Allow"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;have this rule be above your "Security Group A" "Web-Browsing" rule. &amp;nbsp;This above rule will only allow users access to the URL "download.citrixonline.com" and will allow them to download .exe files.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 16:57:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93347#M43823</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-06-29T16:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EXE files but allowing file names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93390#M43843</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Brandon,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding the download.citrix URL to the category alone didn't resolve the issue, however I believe I have fixed it. In the traffic logs, when accessing the GoToMeeting link I saw an IP address which then after an nslookup resolved to apiglobal.gotomeeting.com. I added this as well to the custom URL category which allowed me to use GoToMeeting and still block EXE files.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jack&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 10:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-exe-files-but-allowing-file-names/m-p/93390#M43843</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-30T10:33:59Z</dc:date>
    </item>
  </channel>
</rss>

