<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Type=Deny while  Action=Allow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/154669#M50928</link>
    <description>In my case the application was not identified when using the Facebook App (shows just SSL). Interesting enough, when using Chrome one the iPhone, it identifies it as Facebook-Video. So I had to create a rule to exempt any Social-Network category for iPhones, which isn't ideal, but it was the lowest denominator. Otherwise I have to exclude iPhone from decryption all together or at least iPhones SSL.</description>
    <pubDate>Mon, 01 May 2017 13:08:25 GMT</pubDate>
    <dc:creator>Hwinter</dc:creator>
    <dc:date>2017-05-01T13:08:25Z</dc:date>
    <item>
      <title>Type=Deny while  Action=Allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/153647#M50702</link>
      <description>&lt;P&gt;When opening iOS Facebook app I''m unable to play a movie... however, from the same device if I login to facbook via browser I can play the video.&lt;/P&gt;&lt;P&gt;I'm trying to find out why the iOS App is getting blocked, as my policies clearly allow it.&lt;/P&gt;&lt;P&gt;Rule iPhones:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Iphone Rule allowing all traffic" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8893i65B3B2CF9D3F864A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="iPhone Policy.JPG" alt="Iphone Rule allowing all traffic" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Iphone Rule allowing all traffic&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Log when using Facebook  via Chrome" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8894iA6A9CAB93C95CAEE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Traffic Allowed.JPG" alt="Log when using Facebook  via Chrome" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Log when using Facebook  via Chrome&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Log when using Facebook via iOS App" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8895i78F1E15970B3B351/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Blocked Traffic.JPG" alt="Log when using Facebook via iOS App" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Log when using Facebook via iOS App&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Decryption Policy" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8896iF561EA0B8BF7C5E3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Decryption Policy.JPG" alt="Decryption Policy" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Decryption Policy&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I'm not sure what I'm missing here. I'm trying to understand what is causing the traffic to be blocked. The only thing I see different is the fact that when the user is using the App PA shows the traffic as SSL and when using the&amp;nbsp;Chrome PA shows it as facebook-Video. However, both should be allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas? I'm running VM-100 on 7.1.9.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 17:26:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/153647#M50702</guid>
      <dc:creator>Hwinter</dc:creator>
      <dc:date>2017-04-21T17:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Type=Deny while  Action=Allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/153657#M50703</link>
      <description>&lt;P&gt;For what is worth, I went&amp;nbsp;to&amp;nbsp;&lt;SPAN&gt;Device tab &amp;gt; Response Pages screen, I unticked the&amp;nbsp;"Enable SSL Opt-out Page" option. After that, it looks like it is working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Response Page" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8898iFC0F7DA3B6A5C57D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Opt Out Response Page.JPG" alt="Response Page" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Response Page&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So I believe the page was sent to the app and it was timing out as there would beno reply. Not exacly what I was execting, but that is the only explanation on my mind.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UPATE: problem still presists. VIdeo must have been cached when I was testing it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 19:17:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/153657#M50703</guid>
      <dc:creator>Hwinter</dc:creator>
      <dc:date>2017-04-21T19:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Type=Deny while  Action=Allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/153861#M50738</link>
      <description>&lt;P&gt;I saw the same behavior. When I ran a packet capture on the traffic, I noticed the client was unable to validate the certificate and closed the connection. The traffic had to be exempted as I couldn't include the Decryption CA root in the application's trusted certificate store.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 20:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/153861#M50738</guid>
      <dc:creator>MangoTango</dc:creator>
      <dc:date>2017-04-24T20:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Type=Deny while  Action=Allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/154669#M50928</link>
      <description>In my case the application was not identified when using the Facebook App (shows just SSL). Interesting enough, when using Chrome one the iPhone, it identifies it as Facebook-Video. So I had to create a rule to exempt any Social-Network category for iPhones, which isn't ideal, but it was the lowest denominator. Otherwise I have to exclude iPhone from decryption all together or at least iPhones SSL.</description>
      <pubDate>Mon, 01 May 2017 13:08:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/154669#M50928</guid>
      <dc:creator>Hwinter</dc:creator>
      <dc:date>2017-05-01T13:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Type=Deny while  Action=Allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/585346#M116865</link>
      <description>&lt;P&gt;How did you exempt the traffic? The rule looks like it should have exempted it already. Do you mean you do not decrypt?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 14:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/type-deny-while-action-allow/m-p/585346#M116865</guid>
      <dc:creator>Kristine.Kartchner</dc:creator>
      <dc:date>2024-04-30T14:12:42Z</dc:date>
    </item>
  </channel>
</rss>

