<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need to block WINSCP application but want to allow ssh in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-block-winscp-application-but-want-to-allow-ssh/m-p/323354#M82623</link>
    <description>&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In sec policy I have allowed for some users only RDP and SSH application. But these users are able to use WINSCP application because WINSCP application also using port 22. I want to block winscp application but allow ssh application. How can we achieve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help us.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mohammed Asik&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2020 06:32:20 GMT</pubDate>
    <dc:creator>MohammedAsik</dc:creator>
    <dc:date>2020-04-17T06:32:20Z</dc:date>
    <item>
      <title>Need to block WINSCP application but want to allow ssh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-block-winscp-application-but-want-to-allow-ssh/m-p/323354#M82623</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In sec policy I have allowed for some users only RDP and SSH application. But these users are able to use WINSCP application because WINSCP application also using port 22. I want to block winscp application but allow ssh application. How can we achieve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help us.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mohammed Asik&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 06:32:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-block-winscp-application-but-want-to-allow-ssh/m-p/323354#M82623</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-04-17T06:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Need to block WINSCP application but want to allow ssh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-block-winscp-application-but-want-to-allow-ssh/m-p/323423#M82639</link>
      <description>&lt;P&gt;If you see it as an application in your traffic monitoring, then you should be able to create a rule, specifically blocking that application before your allow rule. I had to do the same thing with Webdav and Sharepoint in a recent implementation. If the traffic is only showing up as SSL traffic, then I do not think you can specifically block a program/application. Also, since it is SSL type traffic, you will need to do SSL decryption for that traffic before it would be identified as an application other than SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not to go too far on this response, but if it is not a standard application and you are doing SSL decryption, you may be able to create your own custom application that is specific to that WINSCP traffic and block the traffic as described above. Sorry, I do not know much about WINSCP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 14:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-block-winscp-application-but-want-to-allow-ssh/m-p/323423#M82639</guid>
      <dc:creator>BruceBennett</dc:creator>
      <dc:date>2020-04-17T14:28:47Z</dc:date>
    </item>
  </channel>
</rss>

