<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What application will be blocked by App ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/147058#M49313</link>
    <description>&lt;P&gt;for any encrypted traffic that's not getting decrypted, (and also as primary means of categorizing before encryption can take place) AppID will use the SNI (Server Name Indication) which is included in the ssl handshake to identify the application&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so as long as your browser support SNI, you should be getting fairly accurate AppID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in case the browser does not support SNI, AppID will try to identify the app based on the certificate CN, but this may not be as accurate as youtube uses *.google.com (hence AppID would be google-base)&lt;/P&gt;</description>
    <pubDate>Fri, 10 Mar 2017 09:38:44 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-03-10T09:38:44Z</dc:date>
    <item>
      <title>What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146039#M49131</link>
      <description>If we want to blocked video streaming, team viewer, logme in, , youtube etc basis on App ID. We dont have URL filtering license.</description>
      <pubDate>Sun, 05 Mar 2017 07:09:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146039#M49131</guid>
      <dc:creator>Rahimbhamani</dc:creator>
      <dc:date>2017-03-05T07:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146047#M49132</link>
      <description>&lt;P&gt;There are couple of ways to do this,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. &amp;nbsp;go to&amp;nbsp;&lt;A href="https://applipedia.paloaltonetworks.com/" target="_blank"&gt;https://applipedia.paloaltonetworks.com/&lt;/A&gt; &amp;nbsp;and search for the applications that you know that you want to block. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. &amp;nbsp;setup a test machine, and create&amp;nbsp;security rule with test machine as source and place it on the very top of the rule set to allow outbound and have a deny all outbound rule for the test machine after the allow outbound. &amp;nbsp; Enable logging and review the traffic log after each application that you are interested to block (make sure you close application or end the streaming first), you should see the specific app-id identify by the traffic log. &amp;nbsp;Create another deny rule and place it above the allow rule to deny those specific app-id. &amp;nbsp;Repeat until you get them all. &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you did not specific which video streaming services/application, that could be tricky because some services could show up as http-video or SSL (encrypted), &amp;nbsp;you will need test and be a detective for a while. &amp;nbsp; If you want to block those video streaming using SSL, you will need to enable SSH decrpytion, that you may want to search on the technote how to and get URL license as well. &amp;nbsp;Since you may not want to decrypte SSL sessions going to health care, banking site, etc.. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have fun,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2017 16:06:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146047#M49132</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2017-03-05T16:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146061#M49133</link>
      <description>&lt;P&gt;For the most part, App-ID should be sufficient even without SSL decryption since the built-in app definitions use multiple vectors to detect what's being accessed. The easiest approach is just to attempt to do what you wish to block and verify the app is properly detected in the traffic log and then add those apps to a blacklist policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if that's not enough, you can also block by domain, keeping in mind that many apps source from multiple domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I do agree that SSL decryption would be a difficult jump to make without a URL license as banking and healthcare are at least two of the categories you likely don't want to mess with, and there may be even more to worry about in Europe.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2017 22:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146061#M49133</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-05T22:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146111#M49139</link>
      <description>&lt;P&gt;We want to block youtube streaming.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 08:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146111#M49139</guid>
      <dc:creator>Rahimbhamani</dc:creator>
      <dc:date>2017-03-06T08:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146113#M49140</link>
      <description>&lt;P&gt;We want to block youtube streaming via Palo Alto. We create the Custom URL Category "testing" and enter the site "*.youtube.com" (with quotation). We select the testing category in Decrpytion profile and Action "Decrpyt" and Type SSL Forwarding. We create the security policy src:any, destination:any and deny youtube-base. But still we can we view streaming on chrome and firefox.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 08:50:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146113#M49140</guid>
      <dc:creator>Rahimbhamani</dc:creator>
      <dc:date>2017-03-06T08:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146123#M49141</link>
      <description>&lt;P&gt;have you tried application filter to block video apps ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="application filter.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="application filter.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 10:18:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146123#M49141</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-06T10:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146877#M49283</link>
      <description>For this we require Decryption policy right. As per my knowledge, desktop based applucation will be block without ssl decryption and for browser based using https we must use decryption policy.&lt;BR /&gt;&lt;BR /&gt;Another thing i want to know that if i dont have URL filtering license, still i got the ogs what application example google drive go the which URL's.</description>
      <pubDate>Thu, 09 Mar 2017 15:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146877#M49283</guid>
      <dc:creator>Rahimbhamani</dc:creator>
      <dc:date>2017-03-09T15:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146886#M49285</link>
      <description>&lt;P&gt;as I mentioned earlier, while it may sound counterintuitive, Palo Alto AppID is able to identify some apps even when SSL is not decrypted. Obviously it can't inspect traffic, but it can use other environmental aspects to help categorize traffic. PA won't disclose all the attributes AppID uses, but obviously if someone is going to youtube.com, they're likely using the youtube-base app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can witness this yourself in the PA traffic logs.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 15:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/146886#M49285</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-09T15:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: What application will be blocked by App ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/147058#M49313</link>
      <description>&lt;P&gt;for any encrypted traffic that's not getting decrypted, (and also as primary means of categorizing before encryption can take place) AppID will use the SNI (Server Name Indication) which is included in the ssl handshake to identify the application&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so as long as your browser support SNI, you should be getting fairly accurate AppID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in case the browser does not support SNI, AppID will try to identify the app based on the certificate CN, but this may not be as accurate as youtube uses *.google.com (hence AppID would be google-base)&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 09:38:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-application-will-be-blocked-by-app-id/m-p/147058#M49313</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-10T09:38:44Z</dc:date>
    </item>
  </channel>
</rss>

