<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Blocking Continue Page  in a TLS connection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302296#M78802</link>
    <description>&lt;P&gt;This is always one issue that strikes a chord with users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is really how the webpage is created and not much about how the FW is configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Read this below article.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2019 22:50:59 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-12-05T22:50:59Z</dc:date>
    <item>
      <title>File Blocking Continue Page  in a TLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302281#M78800</link>
      <description>&lt;P&gt;Hello everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a PA-VM in version 9.0 .1 ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have setup a File-blocking profile and attached it to my allow-all security policy. The File-Blocking profile has the action of "Continue" for ".exe" file type.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the other hand, I configured a decryption policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is that when I try to download an .exe file via HTTP I get the "Continue" response page . However when I try to download the same file via HTTPS the download is blocked and no response page is display.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know why the response page is not displayed when the file is downloaded via a TLS connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;karim&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 21:16:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302281#M78800</guid>
      <dc:creator>karimanizer</dc:creator>
      <dc:date>2019-12-05T21:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: File Blocking Continue Page  in a TLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302296#M78802</link>
      <description>&lt;P&gt;This is always one issue that strikes a chord with users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is really how the webpage is created and not much about how the FW is configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Read this below article.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 22:50:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302296#M78802</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-12-05T22:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: File Blocking Continue Page  in a TLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302497#M78825</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-L4-Transporter lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304" target="_self"&gt;&lt;SPAN class=""&gt;SteveCantwell,&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L4-Transporter lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Thanks for your reply ,&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L4-Transporter lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;I tried to dig deeper in this and wanted to see if the firewall was actually sending the continue page on the wire. I took a pcap on the client side and decrypted the traffic and I do not see the continue page sent on the wire.&amp;nbsp; I see only the reset sent by the firewall.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L4-Transporter lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Non_Working_Continue_Page.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22891i461FF352C9A5CF75/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Non_Working_Continue_Page.JPG" alt="Non_Working_Continue_Page.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L4-Transporter lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;I then performed&amp;nbsp; the test via HTTP (without changing the paloalto configuration) and here I see the correct 503 response from the firewall.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Working_Continue_Page.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22892iBE40039C39989D7C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Working_Continue_Page.JPG" alt="Working_Continue_Page.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anyone know why the response page is not sent by the firewall when using TLS connection&amp;nbsp; ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Many thanks, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Karim&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Dec 2019 18:56:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302497#M78825</guid>
      <dc:creator>karimanizer</dc:creator>
      <dc:date>2019-12-07T18:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: File Blocking Continue Page  in a TLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302525#M78831</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94753"&gt;@karimanizer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Expected behavior. As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;already mentioned by linking the article Gwesson made, the firewall can't send a text/html mime-type if the browser is only going to accept a specified response. With 9.0 a change was made so that it simply resets the connection instead of presenting something that isn't going to be accepted by the browser anyways so you don't have to wait for the timeout.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to user experience, it's better if the firewall simply resets this connection instead of attempting to send an invalid response type.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 06:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302525#M78831</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-08T06:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: File Blocking Continue Page  in a TLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302569#M78840</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;|&amp;nbsp;&lt;SPAN&gt;With 9.0 a change was made so that it simply resets the connection instead ...&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks for the clarification !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article you are referencing seems to say that the firewall always sends the "Continue" page and it was the browser that sometimes, due to mime-type mismatch,&amp;nbsp; does not display the page.&amp;nbsp; Which is not exactly true.&amp;nbsp; So I thought I had something wrong in my config.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for both of you,&lt;/P&gt;&lt;P&gt;Karim&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 20:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/302569#M78840</guid>
      <dc:creator>karimanizer</dc:creator>
      <dc:date>2019-12-08T20:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: File Blocking Continue Page  in a TLS connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/305123#M79284</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently discover that CheckPoint firewalls solve this problem by redirecting the client to another page instead of responding to the initial GET request with a blocking page.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that Palo will introduce this feature in later release &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;karim&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2019 15:23:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-continue-page-in-a-tls-connection/m-p/305123#M79284</guid>
      <dc:creator>karimanizer</dc:creator>
      <dc:date>2019-12-29T15:23:21Z</dc:date>
    </item>
  </channel>
</rss>

