<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Want to allow SFTP only and not SSH Traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308466#M80019</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/116069"&gt;@SahulH&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes there is indeed an open feature request for this (to differentiate SFTP from SSH in APP-ID).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please reach out to your local SE and have him add your vote to the FR:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;&lt;STRONG&gt;FR ID:&lt;/STRONG&gt; 2555&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Wed, 29 Jan 2020 11:35:41 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2020-01-29T11:35:41Z</dc:date>
    <item>
      <title>Want to allow SFTP only and not SSH Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308459#M80017</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to achieve my requirement however, unable to achieve it. Please review my requirement below and suggest your thoughts if there are any possible way to accomplish.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to block SSH traffic and at the same time i need to allow SFTP traffic for our users. I have referred to some KB Article and that states in order to allow the SFTP traffic we need to allow SSH application. So if in this case Normal SSH Traffic also will get allowed. So please share your thoughts for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHtCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHtCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClOPCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClOPCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also i can see that, there is a feature request for creating a separate App ID for SFTP (Link Mentioned below). Can i know the status on that as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="collab-selectable-content-wrapper"&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/How-to-restrict-FTP-and-SFTP-access-using-a-security-policy/m-p/6617#M4837" target="_blank" rel="noopener noreferrer"&gt;https://live.paloaltonetworks.com/t5/General-Topics/How-to-restrict-FTP-and-SFTP-access-using-a-security-policy/m-p/6617#M4837&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Awaiting for your response !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Sahul Hameed&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 11:19:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308459#M80017</guid>
      <dc:creator>SahulH</dc:creator>
      <dc:date>2020-01-29T11:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Want to allow SFTP only and not SSH Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308466#M80019</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/116069"&gt;@SahulH&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes there is indeed an open feature request for this (to differentiate SFTP from SSH in APP-ID).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please reach out to your local SE and have him add your vote to the FR:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;&lt;STRONG&gt;FR ID:&lt;/STRONG&gt; 2555&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 29 Jan 2020 11:35:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308466#M80019</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-01-29T11:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Want to allow SFTP only and not SSH Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308470#M80020</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response on my query, Also i want to know is there of any way to accomplish the necessary requirement in our Current scenario without having a separate App ID for SFTP. To block SSH and allow only SFTP traffic. Do let us know on this as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Sahul Hameed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 11:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308470#M80020</guid>
      <dc:creator>SahulH</dc:creator>
      <dc:date>2020-01-29T11:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Want to allow SFTP only and not SSH Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308502#M80025</link>
      <description>&lt;P&gt;Since SFTP is just FTP over SSH, it implicitly is just SSH. So without deeper inspection of the packets by the AppID enigne there is no way to a SSH terminal over SFTP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 14:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308502#M80025</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-01-29T14:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Want to allow SFTP only and not SSH Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308531#M80034</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;How about a whitelist that allows your users to only sites that are approved?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 16:20:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308531#M80034</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-29T16:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Want to allow SFTP only and not SSH Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308700#M80070</link>
      <description>&lt;P&gt;Agreed!&amp;nbsp; SFTP is just an FTP feature traversing over SSH.&amp;nbsp; They are essentially the same protocol.&amp;nbsp; You would have to have some crazy man-in-the-middle encrypt/decrypt to even attempt this.&amp;nbsp; This sounds a lot like security engineer over-reach or misunderstanding of protocols.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 14:51:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-allow-sftp-only-and-not-ssh-traffic/m-p/308700#M80070</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2020-01-30T14:51:59Z</dc:date>
    </item>
  </channel>
</rss>

