<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block Wetransfer Upload in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229466#M65971</link>
    <description>&lt;P&gt;I was doing a test on allowing wetransfer download, but not allowing upload. Ran into some issues. I have TLS decryption enabled. I have removed the *.wetransfer.com decryption exclusion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My security policy is looking for applications "wetransfer" and "amazon-cloud-drive-uploading". I have a file blocking policy that is set to block upload of any application - any files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I go to wetransfer.com, I can upload any file that I wish&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone successfully doing this?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2018 21:27:57 GMT</pubDate>
    <dc:creator>ce1028</dc:creator>
    <dc:date>2018-09-04T21:27:57Z</dc:date>
    <item>
      <title>Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229466#M65971</link>
      <description>&lt;P&gt;I was doing a test on allowing wetransfer download, but not allowing upload. Ran into some issues. I have TLS decryption enabled. I have removed the *.wetransfer.com decryption exclusion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My security policy is looking for applications "wetransfer" and "amazon-cloud-drive-uploading". I have a file blocking policy that is set to block upload of any application - any files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I go to wetransfer.com, I can upload any file that I wish&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone successfully doing this?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 21:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229466#M65971</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-04T21:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229473#M65972</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Do you block connections that cannot be decrypted?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 21:32:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229473#M65972</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-04T21:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229478#M65975</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;no, in this lab, I do not have a decryption profile assigned. It's set to none&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 00:54:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229478#M65975</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-05T00:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229756#M66057</link>
      <description>&lt;P&gt;Issue turned out to be related to another issue I had.&amp;nbsp; However, now I see a bigger problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can configure a wetransfer download rule without an issue.&amp;nbsp; However, creating a rule that ONLY allows upload to wetransfer is proving to be an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only way to get it to work is to create a rule that looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source zone: trust&lt;/P&gt;&lt;P&gt;source user: mydomain\wetransferuploadusers&lt;/P&gt;&lt;P&gt;destination zone: untrust&lt;/P&gt;&lt;P&gt;applications: web-browsing/ssl&lt;/P&gt;&lt;P&gt;Service: TCP/80, TCP/443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is an issue, because this will allow uploads to any site that's allowed, that runs over 80/443, and any internet traffic these specific users do will match this rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There has to be a better way, just haven't found one yet&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 15:49:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229756#M66057</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-06T15:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229818#M66076</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So maybe I missed something here, but you&amp;nbsp;&lt;EM&gt;aren't&lt;/EM&gt; actually doing decryption of this traffic at all? You won't be able to block uploads as you can't identify the traffic. Therefore you can't distinguish what is actually happening behind that SSL tunnel and you won't be able to identify&amp;nbsp;&lt;SPAN&gt;amazon-cloud-drive-uploading to properly block this. You could use QoS to drastically slow down any uploads to make it unlikely anyone will actually use it, but you can't block it outright.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;+&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 20:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229818#M66076</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-06T20:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229837#M66086</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;So, originally, I was decrypting the traffic because I disabled the "*.wetransfer.com" decrypted exception that Palo adds under SSL Decryption Exclusion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With decryption disabled, I'm still able to block wetransfer uploads using a file blocking policy (although small files, like 100k upload even with file blocking on, but that's another issue).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm attempting to do now is the opposite. I've already successfully blocked uploads, but now I want to allow uploads for specific users.&amp;nbsp; The issue is, with decryption on or off, palo only identifies this traffic as web-browsing and ssl.&amp;nbsp; It does not categorize the upload as amazon-cloud-drive-upload, although it should.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There does not seem to be a good way to allow uploads to only wetransfer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update: Just to be clear, I always had TLS Decryption enabled. When I mentioned disabled decryption, I was referring the "SSL Decryption Exclusion"&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 23:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/229837#M66086</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-06T23:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230029#M66140</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same issue. Assuming you are in the US.&amp;nbsp;&amp;nbsp;You can do this as a workaround. Keep your download&amp;nbsp;security policy rule and create an upload&amp;nbsp;security policy rule that looks like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination Zone: untrust&lt;/P&gt;&lt;P&gt;Destination Address: wetransfer-us-prod-outgoing.s3.amazonaws.com&amp;nbsp;&amp;nbsp;&amp;nbsp; (need an address object)&lt;/P&gt;&lt;P&gt;Application: web-browsing, ssl&lt;/P&gt;&lt;P&gt;Service:&amp;nbsp; TCP_80, TCP_443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For EU, use wetransfer-eu-prod-outgoing.s3.amazonaws.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 17:33:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230029#M66140</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2018-09-07T17:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230076#M66159</link>
      <description>&lt;P&gt;My apologies, I typed this too fast. You don't need an address object.&amp;nbsp; Create a custom URL category containing the below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;wetransfer-us-prod-outgoing.s3.amazonaws.com&lt;/P&gt;&lt;P&gt;wetransfer-us-prod-outgoing.s3.amazonaws.com/*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then in the policy rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination Zone: untrust&lt;/P&gt;&lt;P&gt;Destination Address: any&lt;/P&gt;&lt;P&gt;Application: web-browsing, ssl&lt;/P&gt;&lt;P&gt;Service: tcp-443&lt;/P&gt;&lt;P&gt;URL Category:&amp;nbsp; &amp;lt;name of custom URL category&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 15:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230076#M66159</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2018-09-08T15:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230107#M66164</link>
      <description>&lt;P&gt;This worked, thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only problem now is I don't see this traffic in the URL Filtering log. If you specify the custom url category in the security policy rule, does that mean its no longer logged?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 02:22:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230107#M66164</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-10T02:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230113#M66165</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&lt;/P&gt;&lt;P&gt;URL logs are only generated by the URL filtering security profiles. When you add URL categories directly to the security policy, you are able to filter on URLs directly there but without also adding an URL filtering security profile, no URL log is generated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in this case because you already restrict the rule to a custom URL category you could add a Log-All profile and you should see the URL logs.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 06:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230113#M66165</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-10T06:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230260#M66193</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;but I added a url filtering profile and set some of the categories to "alert". I see my custom url category there too and set that to alert, but no dice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you mean by 'log-all' profile? How is that setup?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 02:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230260#M66193</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-11T02:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230323#M66206</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&lt;/P&gt;&lt;P&gt;What I meant with this log all profile is an URL filteting profile like the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Set all categories to action "alert" (The custom ones I would set to "none" but this is up to you)&lt;/LI&gt;&lt;LI&gt;Disable the checkbox at "Log container page only" (helpful in your case, but depending on the art of connection it could generate quite a few logs&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Is my assumption correct that the profile that you applied has the log container page only checkbox activated?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 10:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230323#M66206</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-11T10:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230523#M66242</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;you were correct, the Log container page only option was enabled. I disabled and now it's logged.&amp;nbsp; Question though, did I have to uncheck the log container page only because I used the custom url category in the security policy rule, or is it unrelated?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 01:57:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230523#M66242</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-12T01:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230551#M66246</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&lt;/P&gt;&lt;P&gt;With that option enabled the firewall only logs specific MIME types. This option should enable URL logging without generating potentially extremely high logrates (modern websites - spcially highly dynamic websites - where javascript loads content in the background, keepalives are sent and javascripts, images, css that are fetched from everywhere in the internet will generate high amounts of logs that are not very useful in most cases).&lt;/P&gt;&lt;P&gt;In your case the requests to the domains in your custom URL category are not matching the &lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/url-filtering/url-filtering-concepts/container-pages#id5cc782d9-3f7b-4958-bab6-7d50816ee6ed" target="_self"&gt;default MIME types&lt;/A&gt; so they were not logged. You have now the option to keep this config with the log container page only disabled or you add the MIME type used for this website to the Container pages config.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 09:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230551#M66246</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-12T09:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230640#M66263</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;thank you for clarifying. For this purpose, I shall create a seperate URL profile and turn the option off&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 23:35:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/230640#M66263</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-12T23:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/250920#M71353</link>
      <description>&lt;P&gt;Hi MikeC, quick question please. Do we need set this policy (with &lt;SPAN&gt;wetransfer-eu-prod-outgoing.s3.amazonaws.com&lt;/SPAN&gt;) to Deny Action? And then create rule with allow using&amp;nbsp;&lt;SPAN&gt;wetransfer?&lt;/SPAN&gt;&amp;nbsp;This link only for uploading? Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 15:24:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/250920#M71353</guid>
      <dc:creator>Olha_Osadcha</dc:creator>
      <dc:date>2019-02-22T15:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Block Wetransfer Upload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/251046#M71385</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not to deny. In my situation, I always block uploads with a File Blocking policy.&amp;nbsp; What I needed was to allow uploads for only wetransfer. Since PAN was seeing the wetransfer upload traffic as application 'ssl', I need to add these urls to allow uploading only for wetransfer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you typically allow uploading and want to only block wetransfer uploads, then yes, you can use deny action&lt;/P&gt;</description>
      <pubDate>Sat, 23 Feb 2019 02:10:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-wetransfer-upload/m-p/251046#M71385</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2019-02-23T02:10:16Z</dc:date>
    </item>
  </channel>
</rss>

