<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Block browser extensions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-browser-extensions/m-p/269307#M74605</link>
    <description>&lt;P&gt;Have you enabled SSL Decryption?&amp;nbsp; Since the Chrome Web Store runs over SSL, and if you're not using SSL Decryption, then your choice becomes permitting all extensions or blocking all extensions.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, if you focus on the traffic generated by the "searchencrypt" extension - that's something much easier to target without collatteral damage.&amp;nbsp; You're not necessarily stopping users from downloading the extension, but these options will prevent the extension from working.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easiest way would be to use the URL Filtering engine and block the "proxy-avoidance-and-anonymizers" URL category - that will stop the searchencrypt extension from working.&amp;nbsp; Two upsides to this method:&amp;nbsp; 1.) it would block other/similar extensions which have been categorized as proxies by our URL filtering engine, and 2.) it can provide some visual feedback through the URL Response Pages.&amp;nbsp; The error page can be customized to your environment and provide additional information to the user receiving the message.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a screenshot after blocking that URL category:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="searchencrypt.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20370i4A952E2083BEDEC9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="searchencrypt.PNG" alt="searchencrypt.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't have the URL filtering subscription, I believe you can still create custom URL categories.&amp;nbsp; Add "searchencrypt.com" and "*.searchencrypt.com" to a custom URL category and deny access to that category.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another option if you don't have the URL filtering subscription:&amp;nbsp; create a custom AppID signature.&amp;nbsp; I configured one that looks for "searchencrypt.com" in the SSL Response Certificate context of the SSL decoder.&amp;nbsp; Here's a screenshot with most of the information you'd need to create the custom application signature:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="searchencrypt2.PNG" style="width: 394px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20371iE6EC4631E775CFC6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="searchencrypt2.PNG" alt="searchencrypt2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And here's a screenshot from the traffic log showing it blocking based on the custom AppID signature:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appid-searchencrypt.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20372i8E2FA2B426F5E844/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="appid-searchencrypt.PNG" alt="appid-searchencrypt.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2019 16:49:16 GMT</pubDate>
    <dc:creator>jvalentine</dc:creator>
    <dc:date>2019-06-12T16:49:16Z</dc:date>
    <item>
      <title>How to Block browser extensions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-browser-extensions/m-p/269258#M74599</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody know if it is possible to block specific browser extensions from being downloaded?&lt;/P&gt;&lt;P&gt;I would like to block the searchencrypt browser extension.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 15:39:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-browser-extensions/m-p/269258#M74599</guid>
      <dc:creator>KatiaNunez</dc:creator>
      <dc:date>2019-06-12T15:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to Block browser extensions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-browser-extensions/m-p/269307#M74605</link>
      <description>&lt;P&gt;Have you enabled SSL Decryption?&amp;nbsp; Since the Chrome Web Store runs over SSL, and if you're not using SSL Decryption, then your choice becomes permitting all extensions or blocking all extensions.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, if you focus on the traffic generated by the "searchencrypt" extension - that's something much easier to target without collatteral damage.&amp;nbsp; You're not necessarily stopping users from downloading the extension, but these options will prevent the extension from working.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easiest way would be to use the URL Filtering engine and block the "proxy-avoidance-and-anonymizers" URL category - that will stop the searchencrypt extension from working.&amp;nbsp; Two upsides to this method:&amp;nbsp; 1.) it would block other/similar extensions which have been categorized as proxies by our URL filtering engine, and 2.) it can provide some visual feedback through the URL Response Pages.&amp;nbsp; The error page can be customized to your environment and provide additional information to the user receiving the message.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a screenshot after blocking that URL category:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="searchencrypt.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20370i4A952E2083BEDEC9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="searchencrypt.PNG" alt="searchencrypt.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't have the URL filtering subscription, I believe you can still create custom URL categories.&amp;nbsp; Add "searchencrypt.com" and "*.searchencrypt.com" to a custom URL category and deny access to that category.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another option if you don't have the URL filtering subscription:&amp;nbsp; create a custom AppID signature.&amp;nbsp; I configured one that looks for "searchencrypt.com" in the SSL Response Certificate context of the SSL decoder.&amp;nbsp; Here's a screenshot with most of the information you'd need to create the custom application signature:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="searchencrypt2.PNG" style="width: 394px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20371iE6EC4631E775CFC6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="searchencrypt2.PNG" alt="searchencrypt2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And here's a screenshot from the traffic log showing it blocking based on the custom AppID signature:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appid-searchencrypt.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20372i8E2FA2B426F5E844/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="appid-searchencrypt.PNG" alt="appid-searchencrypt.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 16:49:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-browser-extensions/m-p/269307#M74605</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2019-06-12T16:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to Block browser extensions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-browser-extensions/m-p/269308#M74606</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;thanks for your help.&lt;/P&gt;&lt;P&gt;I will try with blocking the url. If that does not work, I will use the other 2 suggestions you explained. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 17:14:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-browser-extensions/m-p/269308#M74606</guid>
      <dc:creator>KatiaNunez</dc:creator>
      <dc:date>2019-06-12T17:14:12Z</dc:date>
    </item>
  </channel>
</rss>

