<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External email attachments in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145888#M49113</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We allow our users to check personal email externally(gmail/yahoo/etc). I'd like to prevent them from downloading attachments from these external emails if&amp;nbsp;possible. Can this be done and how?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reason being, downloading attachments directly to the desktop bypasses our other lines of defense. We'd like to force them to forward said message to a work email address and allow our mail&amp;nbsp;appliances do there job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edited: I suppose I should have mentioned LOL, we use a Palo Alto Next Firewall for our edge device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions...&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2017 21:37:09 GMT</pubDate>
    <dc:creator>Crash28</dc:creator>
    <dc:date>2017-03-02T21:37:09Z</dc:date>
    <item>
      <title>External email attachments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145888#M49113</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We allow our users to check personal email externally(gmail/yahoo/etc). I'd like to prevent them from downloading attachments from these external emails if&amp;nbsp;possible. Can this be done and how?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reason being, downloading attachments directly to the desktop bypasses our other lines of defense. We'd like to force them to forward said message to a work email address and allow our mail&amp;nbsp;appliances do there job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edited: I suppose I should have mentioned LOL, we use a Palo Alto Next Firewall for our edge device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions...&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 21:37:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145888#M49113</guid>
      <dc:creator>Crash28</dc:creator>
      <dc:date>2017-03-02T21:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: External email attachments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145914#M49115</link>
      <description>&lt;P&gt;short answer: file blocking&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/threat-prevention/set-up-file-blocking" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/threat-prevention/set-up-file-blocking&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;longer answer: especially with email sites, it will require decryption as Palo Alto won't be able to see the traffic otherwise.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 02:44:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145914#M49115</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-03T02:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: External email attachments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145952#M49119</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30157"&gt;@Crash28&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;In a very round-about way you could get something like this to function as is, even without decryption to an extent. You would need to gather the IP addresses for gmail, yahoo, and any other email service (I recommend setting up MineMeld for this) I'm not positive if there is a miner&amp;nbsp;for this already but Google makes it pretty easy to get the IP ranges being used. Once you have the IP ranges you could create a rule with a special file blocking profile to block all of the attachments from that range, then you would just have to notify your employees of the changes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In general though if your allowing users to check personal email at work I wouldn't really recommend doing something like this, your going to increase support calls by quite a bit since the download is going to fail. If this is a legitimate concern I would just get the okay to block personal email access.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 14:18:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145952#M49119</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-03T14:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: External email attachments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145956#M49122</link>
      <description>&lt;P&gt;&amp;gt;In a very round-about way you could get something like this to function as is, even without decryption to an extent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not trying to be combatitive, but how so? gmail forces https, for example, and with https, all the headers are encrypted. you can't tell someone is requesting an exe resource, let alone analyze the traffic to determine it's a PE (which is what PA is actually doing with file blocking), so I'm at a loss seeing how it'll work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if I am misunderstanding, please let me know.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 15:01:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145956#M49122</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-03T15:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: External email attachments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145980#M49126</link>
      <description>&lt;P&gt;Nope that's my bad, I just took another look at what I've configured previously and it wasn't a file block it was a QOS profile that just made it painfully slow to download anything from those sites in an attempt to get people to stop doing it. To trully file block you would need the decryption profile to be setup. That's my bad I thought that we had configured it to block it all-together.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That being said you could do the custom QOS profile and QOS policy and just make it really inconvient for them in an attempt to get them to stop doing it if you aren't in a position to just decrypt the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 17:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-email-attachments/m-p/145980#M49126</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-03T17:32:31Z</dc:date>
    </item>
  </channel>
</rss>

