<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245954#M70071</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37892"&gt;@j.moore&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can't use variables for this.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jan 2019 18:10:31 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-01-14T18:10:31Z</dc:date>
    <item>
      <title>GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245806#M70031</link>
      <description>&lt;P&gt;Does anyone have any ideas on how to permit access to Google Maps but block access to all other Google&amp;nbsp;services? I have tried using a rule matching the Google-Maps application&amp;nbsp;however it requires google-base which allows many other Google services. I have also tried using custom&amp;nbsp;URLs for maps.google.com and &lt;A href="http://www.google.com/maps" target="_blank"&gt;www.google.com/maps&lt;/A&gt;; however, Google maps seems to require access to resources at &lt;A href="http://www.google.com/" target="_blank"&gt;www.google.com/&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer is currently using a Squid proxy&amp;nbsp;with detailed regex expressions to accomplish this. Below are some examples. They would like to remove the proxy and use the firewall only.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;acl ALLOWED_URL url_regex -i ^https?://&lt;A href="http://www.google.com/favicon.ico$" target="_blank"&gt;www.google.com/favicon.ico$&lt;/A&gt;&lt;BR /&gt;acl ALLOWED_URL url_regex -i ^https?://&lt;A href="http://www.google.com/images/branding/product/ico" target="_blank"&gt;www.google.com/images/branding/product/ico&lt;/A&gt;&lt;BR /&gt;acl ALLOWED_URL url_regex -i ^https?://www\.google\.com/(maps|xjs)&lt;BR /&gt;acl ALLOWED_URL url_regex -i ^https?://www\.google\.com/s(earch)?\?tbm=map&lt;BR /&gt;acl ALLOWED_URL url_regex -i ^https?://www\.google\.com/gen_204\?oq=&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jan 2019 23:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245806#M70031</guid>
      <dc:creator>j.moore</dc:creator>
      <dc:date>2019-01-13T23:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245828#M70034</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37892"&gt;@j.moore&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why don't you add the same URLs (without regex) to your custom URL category?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 01:15:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245828#M70034</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-14T01:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245873#M70047</link>
      <description>&lt;P&gt;I tried that. It doesn't seem to match on the full string. I think Custom URLs only support domains and subdomains, not the variables.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 12:51:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245873#M70047</guid>
      <dc:creator>j.moore</dc:creator>
      <dc:date>2019-01-14T12:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245954#M70071</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37892"&gt;@j.moore&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can't use variables for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 18:10:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245954#M70071</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-14T18:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245955#M70072</link>
      <description>&lt;P&gt;I figured that. What other options do I have?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 18:12:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245955#M70072</guid>
      <dc:creator>j.moore</dc:creator>
      <dc:date>2019-01-14T18:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245956#M70073</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37892"&gt;@j.moore&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;To do this easily and cleanly you don't really have any from the firewall directly. Google integrates all of their services pretty tightly and trying to limit all of Google but allowing Maps would require a very large amount of allowed URLs that will likely be constantly changing and breaking things.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 18:16:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245956#M70073</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-14T18:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245993#M70084</link>
      <description>&lt;P&gt;Using a squid proxy this is fairly straightforward. Hoping this might be accomplished&amp;nbsp;using the PA firewall only.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 21:29:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/245993#M70084</guid>
      <dc:creator>j.moore</dc:creator>
      <dc:date>2019-01-14T21:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246140#M70113</link>
      <description>&lt;P&gt;As they work with squid, did you add these urls to the custom url category?&lt;/P&gt;&lt;PRE&gt;www.google.com/favicon.ico
www.google.com/images/branding/product/ico
www.google.com/maps
www.google.com/xjs
www.google.com/search?tbm=map
www.google.com/s?tbm=map
www.google.com/gen_204?oq=&lt;/PRE&gt;</description>
      <pubDate>Tue, 15 Jan 2019 19:50:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246140#M70113</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-15T19:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246193#M70125</link>
      <description>&lt;P&gt;Yes, but it fails to match the following.&amp;nbsp; I I think this is because&amp;nbsp;PANOS only matches on domains, subdomains,&amp;nbsp;and paths not Parameters.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;www.google.com/search?tbm=map
www.google.com/s?tbm=map
www.google.com/gen_204?oq=&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 00:47:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246193#M70125</guid>
      <dc:creator>j.moore</dc:creator>
      <dc:date>2019-01-16T00:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246194#M70126</link>
      <description>&lt;P&gt;Are you doing SSL Decryption? Without decryption, the firewall doesn't even see the HTTP request for the maps page, it only sees the hostname of the server they're connecting to, in this case it's &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; as the host. Google uses a wildcard cert, so the response from the server is for *.google.com. Since neither is distinguishing the maps service, there would be no way to allow maps but deny others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-DB does categorize on full URIs, not just domains and hosts. A good example of this is any of the test sites:&lt;/P&gt;&lt;P&gt;&lt;A href="https://pandb.paloaltonetworks.com/test-gambling" target="_blank"&gt;https://pandb.paloaltonetworks.com/test-gambling&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://pandb.paloaltonetworks.com/test-phishing" target="_blank"&gt;https://pandb.paloaltonetworks.com/test-phishing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both of those pages are on the same host and domain, but different paths. PAN-DB will categorize them appropriately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you're not decrypting the SSL (TLS) traffic, the only thing the firewall will see is a TLS Client Hello that has "pandb.paloaltonetworks.com" but not the full URI.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 00:56:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246194#M70126</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-01-16T00:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246195#M70127</link>
      <description>&lt;P&gt;Even with Decryption&amp;nbsp;enabled PANOS still doesn't match the Parameters&amp;nbsp;in the URL. Path matching&amp;nbsp;works; however,&amp;nbsp; without matching the parameters&amp;nbsp;we can't differentiate&amp;nbsp;between Google&amp;nbsp;maps and all other Google&amp;nbsp;services.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 01:05:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246195#M70127</guid>
      <dc:creator>j.moore</dc:creator>
      <dc:date>2019-01-16T01:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246197#M70129</link>
      <description>&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Even with Decryption&amp;nbsp;enabled PANOS still doesn't match the Parameters&amp;nbsp;in the URL.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That's actually incorrect - PAN-DB (and PAN-OS) does do full URI matching. The two test URLs I provided would illustrate that. The "test-phishing" and "test-gambling" parts are neither the host nor the domain. Those are part of the path, and PAN-DB definitely does page-level categorization, even when you define a custom URL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looking at the squid rules you provided, you would likely need to create a custom URL category with all of the following URLs. :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.google.com/favicon.ico" target="_blank"&gt;www.google.com/favicon.ico&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.google.com/images/branding/product/ico" target="_blank"&gt;www.google.com/images/branding/product/ico&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.google.com/maps*" target="_blank"&gt;www.google.com/maps*&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.google.com/xjs*" target="_blank"&gt;www.google.com/xjs*&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.google.com/s?tpm=map" target="_blank"&gt;www.google.com/s?tpm=map&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.google.com/search?tpm=map" target="_blank"&gt;www.google.com/search?tpm=map&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.google.com/gen_204/?oq=*" target="_blank"&gt;www.google.com/gen_204/?oq=*&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You may want to double up on those, excluding the 'www' since it's valid even without that.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 01:13:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/246197#M70129</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-01-16T01:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: GOOGLE MAPS WHILE BLOCKING OTHER GOOGLE SERVICES</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/434101#M95946</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37892"&gt;@j.moore&lt;/a&gt;&amp;nbsp;I never tried this in palo alto but i did it in Cyberoam firewall. We applied this to one of our client where they had to use only google maps and block all other google services. There we allowed google maps and blocked other services using SSL certificate. Its been quite few years that we implemented this.&amp;nbsp;&lt;A href="https://support.sophos.com/support/s/article/KB-000038926?language=en_US" target="_blank"&gt;https://support.sophos.com/support/s/article/KB-000038926?language=en_US&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this will help&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 10:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-maps-while-blocking-other-google-services/m-p/434101#M95946</guid>
      <dc:creator>vnkychandu</dc:creator>
      <dc:date>2021-09-15T10:27:28Z</dc:date>
    </item>
  </channel>
</rss>

