<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic rules to allow webinars while blocking http-audio and http-video in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181399#M56039</link>
    <description>&lt;P&gt;We block most http-audio/video in our enterprise but we allow access to webcasts/webinars. We have had to resort to create a "webinar" rule allowing http-audio and video, rtmp, rtmpe, gotowebinar, and more... with specific IP ranges. Because these change often we have to keep adding CDN IPs to this rule for people to see/hear the webinars. This includes adding a flavor of default URL categories to match the rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apart from playing whack-a-mole, the concern is that allowing those ranges with, say, the business-and-economy, content-delivery-networks or streaming-media rule will allow traffic matching that security policy rule for sites unrelated to online webinars or courses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a different/easier way to do this while still blocking http-video and audio for anything not related to webinars? Can someone share rules or ideas accomplishing this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Larry&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2017 20:13:56 GMT</pubDate>
    <dc:creator>hvcomputech</dc:creator>
    <dc:date>2017-10-11T20:13:56Z</dc:date>
    <item>
      <title>rules to allow webinars while blocking http-audio and http-video</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181399#M56039</link>
      <description>&lt;P&gt;We block most http-audio/video in our enterprise but we allow access to webcasts/webinars. We have had to resort to create a "webinar" rule allowing http-audio and video, rtmp, rtmpe, gotowebinar, and more... with specific IP ranges. Because these change often we have to keep adding CDN IPs to this rule for people to see/hear the webinars. This includes adding a flavor of default URL categories to match the rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apart from playing whack-a-mole, the concern is that allowing those ranges with, say, the business-and-economy, content-delivery-networks or streaming-media rule will allow traffic matching that security policy rule for sites unrelated to online webinars or courses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a different/easier way to do this while still blocking http-video and audio for anything not related to webinars? Can someone share rules or ideas accomplishing this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Larry&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 20:13:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181399#M56039</guid>
      <dc:creator>hvcomputech</dc:creator>
      <dc:date>2017-10-11T20:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: rules to allow webinars while blocking http-audio and http-video</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181480#M56050</link>
      <description>&lt;P&gt;Hi Larry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It might be easier to use User-ID for this purpose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a 'webinar' user group and have a single rule for them instead of constantly modifying a security rules, you just need to add the people that need access to webinars into the webinar user group on your AD for them to have access. If they're not in the user group then they can match the default-deny rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could combine this with a new feature in Windows Server 2016 which is 'timed group membership'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 11:53:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181480#M56050</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-10-12T11:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: rules to allow webinars while blocking http-audio and http-video</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181572#M56062</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16342"&gt;@hvcomputech&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;&amp;nbsp;has a good idea here, if you aren't running server 2016 it at least makes it so that you only have to worry about one user-id group. If that doesn't work out you can automate this through the API, allowing you to quickly include someone in the webinar rule, and then have a scheduled API call that clears out said users sometime during non-business hours so that it they only have access for a limited amount of time.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 19:30:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181572#M56062</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-10-12T19:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: rules to allow webinars while blocking http-audio and http-video</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181829#M56094</link>
      <description>&lt;P&gt;Another option is use fqdn instead of IP ranges.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 19:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-to-allow-webinars-while-blocking-http-audio-and-http-video/m-p/181829#M56094</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-13T19:42:36Z</dc:date>
    </item>
  </channel>
</rss>

