<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thinking about blocking executable file downloads - Gotchas? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/94677#M43938</link>
    <description>&lt;P&gt;In our environment, we have eliminated the scourge of people being local administrators on computers, with the exception of administrative accounts assigned to some of the IT personnel.&amp;nbsp; I'm thinking about blocking the DLL, DMG, EXE, MSI, and PE file types for everyone but IT personnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any caveats or big gotchas related to doing so?&amp;nbsp; I'm thinking that things like GoToMeeting/WebEx/Skype For Business conferences might be a problem.&amp;nbsp; Are there any good ways to work around that?&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2016 13:06:44 GMT</pubDate>
    <dc:creator>scottsander</dc:creator>
    <dc:date>2016-07-06T13:06:44Z</dc:date>
    <item>
      <title>Thinking about blocking executable file downloads - Gotchas?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/94677#M43938</link>
      <description>&lt;P&gt;In our environment, we have eliminated the scourge of people being local administrators on computers, with the exception of administrative accounts assigned to some of the IT personnel.&amp;nbsp; I'm thinking about blocking the DLL, DMG, EXE, MSI, and PE file types for everyone but IT personnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any caveats or big gotchas related to doing so?&amp;nbsp; I'm thinking that things like GoToMeeting/WebEx/Skype For Business conferences might be a problem.&amp;nbsp; Are there any good ways to work around that?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 13:06:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/94677#M43938</guid>
      <dc:creator>scottsander</dc:creator>
      <dc:date>2016-07-06T13:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: Thinking about blocking executable file downloads - Gotchas?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/94711#M43940</link>
      <description>&lt;P&gt;You need to create 2 security policies.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create a new custom url category.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Then whitelist&amp;nbsp; the urls page where you download trusted urls like gotomeeting etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Then create a file blocking to allow exe download&lt;/LI&gt;&lt;LI&gt;Create security policy above your web-browsing policy and associate above 2 profiles&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you want you can restrict for users also&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create new file blocking profile to block all exe, you can associate with this your web browsing rule or any rule which you want to block exe.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 06 Jul 2016 14:20:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/94711#M43940</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2016-07-06T14:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Thinking about blocking executable file downloads - Gotchas?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/94718#M43941</link>
      <description>&lt;P&gt;I would think about what applications in your environment do automatic updates. Google chrome for example is one app that is always downloading updates in the from of GoogleUpdate.exe. Another thing to consider would be Windows updates as they consist of DLL files I believe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A good way to work around it would be to create a custom URL category that consists of URLs that you are ok with PE files being downloaded from. Then create a new security rule such as 'whitelist .exe' and add this category to it and a new file blocking profile to alert on all files (that way you can confirm only the files you want are getting through via this rule).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps you out!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 14:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/94718#M43941</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-07-06T14:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Thinking about blocking executable file downloads - Gotchas?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/134064#M47302</link>
      <description>&lt;P&gt;How do you handle things when the files don't come from a specific URL, but instead download from Akamai or the like? These can come from many different IP addresses. We are blocking all PE files, but there are some that need to come through and we wind up allowing a specific user to download anything from the internet, which isn't a good solution.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 19:31:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/134064#M47302</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2016-12-21T19:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Thinking about blocking executable file downloads - Gotchas?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/134120#M47305</link>
      <description>&lt;P&gt;The biggest gotchas is going to always be applications that update in the background. You probably don't want to be in a sitaution where you have to spend time upgrading stupid things like Chrome or FireFox. That being said if you manage those already through something like SCCM then it really doesn't matter that much really.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 22:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/thinking-about-blocking-executable-file-downloads-gotchas/m-p/134120#M47305</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-21T22:10:45Z</dc:date>
    </item>
  </channel>
</rss>

