<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exception for threat type &amp;quot;file&amp;quot;? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216819#M62766</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;The matching security rule is "PROD-WEB-WHITELISTED-URLs" (see screenshot) and from there I've followed the path to the file blocking profile:&lt;BR /&gt;&lt;BR /&gt;security rule "PROD-WEB-WHITELISTED-URLs" -&amp;gt; security profile group "ZUR-MITIGATION-NO-URL-FILTER" -&amp;gt; file blocking profile "ZUR-FILE-BLOCK-DEFAULT"&lt;BR /&gt;&lt;BR /&gt;ZUR-FILE-BLOCK-DEFAULT contains 3 rules:&lt;BR /&gt;&lt;BR /&gt;1)&lt;BR /&gt;Name: DOWNLOAD-ALERT-DEFAULT&lt;BR /&gt;Apps: any&lt;BR /&gt;File Types: any&lt;BR /&gt;Direction: download&lt;BR /&gt;Action: alert&lt;BR /&gt;&lt;BR /&gt;2)&lt;BR /&gt;Name: DOWNLOAD-BLOCK-DEFAULT&lt;BR /&gt;Apps: any&lt;BR /&gt;File Types: bat, cmd, cpl, dll, dmg, exe, gzip, iso, lnk, mp3, msi, ocx, pif, powershell, tar, vbe, wmf&lt;BR /&gt;Direction: download&lt;BR /&gt;Action: alert&lt;BR /&gt;&lt;BR /&gt;3)&lt;BR /&gt;Name: UPLOAD-BLOCK-DEFAULT&lt;BR /&gt;Apps: any&lt;BR /&gt;File Types: any&lt;BR /&gt;Direction: upload&lt;BR /&gt;Action: block&lt;BR /&gt;&lt;BR /&gt;I cannot find anything in this file blocking profile that would block a CSV.&lt;BR /&gt;Once again: afaik this file blocking profile hasn't change lately but the CSV download worked before with it. Maybe a bug with one of the latest "Applications and Threats" updates?&lt;BR /&gt;&lt;BR /&gt;I've found following list but I don't understand where exactly the file type IDs are used?&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/FileType-list-with-the-Threat-ID-number/ta-p/56119" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/FileType-list-with-the-Threat-ID-number/ta-p/56119&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;Denis&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSV-blocked-2.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15396iF4E38670086984F7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CSV-blocked-2.jpg" alt="CSV-blocked-2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jun 2018 12:06:55 GMT</pubDate>
    <dc:creator>DenisHierholzer</dc:creator>
    <dc:date>2018-06-06T12:06:55Z</dc:date>
    <item>
      <title>Exception for threat type "file"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216697#M62745</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have following in my logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Threat tpye: file&lt;BR /&gt;Threat name: CSV file&lt;BR /&gt;ID: 52032&lt;BR /&gt;Severity: low&lt;BR /&gt;File Name: xyz.csv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Vulnerability Protection and Anti-Spyware I know how to easily create exceptions for specific IPs/URLs. Is there a way to easily create exceptions the same way for "file threats"?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Furthermore I'm not aware that my file blocking profile says "CSV" or "any" for downloading files...&lt;BR /&gt;This worked fine some days ago afaik.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would I unblock this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Denis&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 17:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216697#M62745</guid>
      <dc:creator>DenisHierholzer</dc:creator>
      <dc:date>2018-06-05T17:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for threat type "file"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216705#M62746</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59908"&gt;@DenisHierholzer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You shouldn't be getting these unless you have a File Blocking profile configured and assigned to this traffic. Can you verify that someone hasn't made any modifications to the profile and isn't alerting/blocking the traffic in any way?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 17:44:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216705#M62746</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-05T17:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for threat type "file"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216819#M62766</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;The matching security rule is "PROD-WEB-WHITELISTED-URLs" (see screenshot) and from there I've followed the path to the file blocking profile:&lt;BR /&gt;&lt;BR /&gt;security rule "PROD-WEB-WHITELISTED-URLs" -&amp;gt; security profile group "ZUR-MITIGATION-NO-URL-FILTER" -&amp;gt; file blocking profile "ZUR-FILE-BLOCK-DEFAULT"&lt;BR /&gt;&lt;BR /&gt;ZUR-FILE-BLOCK-DEFAULT contains 3 rules:&lt;BR /&gt;&lt;BR /&gt;1)&lt;BR /&gt;Name: DOWNLOAD-ALERT-DEFAULT&lt;BR /&gt;Apps: any&lt;BR /&gt;File Types: any&lt;BR /&gt;Direction: download&lt;BR /&gt;Action: alert&lt;BR /&gt;&lt;BR /&gt;2)&lt;BR /&gt;Name: DOWNLOAD-BLOCK-DEFAULT&lt;BR /&gt;Apps: any&lt;BR /&gt;File Types: bat, cmd, cpl, dll, dmg, exe, gzip, iso, lnk, mp3, msi, ocx, pif, powershell, tar, vbe, wmf&lt;BR /&gt;Direction: download&lt;BR /&gt;Action: alert&lt;BR /&gt;&lt;BR /&gt;3)&lt;BR /&gt;Name: UPLOAD-BLOCK-DEFAULT&lt;BR /&gt;Apps: any&lt;BR /&gt;File Types: any&lt;BR /&gt;Direction: upload&lt;BR /&gt;Action: block&lt;BR /&gt;&lt;BR /&gt;I cannot find anything in this file blocking profile that would block a CSV.&lt;BR /&gt;Once again: afaik this file blocking profile hasn't change lately but the CSV download worked before with it. Maybe a bug with one of the latest "Applications and Threats" updates?&lt;BR /&gt;&lt;BR /&gt;I've found following list but I don't understand where exactly the file type IDs are used?&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/FileType-list-with-the-Threat-ID-number/ta-p/56119" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/FileType-list-with-the-Threat-ID-number/ta-p/56119&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;Denis&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSV-blocked-2.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15396iF4E38670086984F7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CSV-blocked-2.jpg" alt="CSV-blocked-2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 12:06:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216819#M62766</guid>
      <dc:creator>DenisHierholzer</dc:creator>
      <dc:date>2018-06-06T12:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for threat type "file"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216846#M62772</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59908"&gt;@DenisHierholzer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would open a TAC case for this and allow support to take a look at this. It doesn't look like this should actively be blocking anything but there may be something within your configuration that is overriding what you have selected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 13:50:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exception-for-threat-type-quot-file-quot/m-p/216846#M62772</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-06T13:50:25Z</dc:date>
    </item>
  </channel>
</rss>

