<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Tor application traffic. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336617#M84807</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135703"&gt;@Yusuf_PA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any web servers which are public facing?&lt;/P&gt;
&lt;P&gt;IF yes then you need security policy from untrust having source address as any to the public ip of web servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source Zone Untrust&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Destination Zone&amp;nbsp; - Where your web servers reside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be careful when you do this as we do not know your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 05 Jul 2020 02:28:47 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-07-05T02:28:47Z</dc:date>
    <item>
      <title>Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336580#M84784</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are planning to block Tor application traffic in our PA device , so do we need to write security policy in both the direction&amp;nbsp; and also share the steps to block the traffic in Palo Alto device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Yusuf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 18:33:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336580#M84784</guid>
      <dc:creator>Yusuf_PA</dc:creator>
      <dc:date>2020-07-03T18:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336590#M84791</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135703"&gt;@Yusuf_PA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It depends on traffic flow if traffic is initiated &amp;nbsp;from the user inside the network then you only need to block the application in security&lt;/P&gt;
&lt;P&gt;rule for traffic from inside to outside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have some Internet facing servers and users access from Internet to access that and it is using port 443 then you need to block&lt;/P&gt;
&lt;P&gt;the application in security rule from outside to inside.&lt;/P&gt;
&lt;P&gt;Also you need to enable ssl decryption for this it is using port 443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 04:47:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336590#M84791</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-04T04:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336610#M84803</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;If you have some Internet facing servers and users access from Internet to access that and it is using port 443 then you need to block&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;the application in security rule from outside to inside.&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;This sounds a little confusing. From external you probably won't detect traffic coming from TOT exit nodes or do you mean when there is a TOR node bebind the paloalto firewall that is publicly available?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 20:39:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336610#M84803</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-07-04T20:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336611#M84804</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135703"&gt;@Yusuf_PA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some help about blocking TOR you can find here:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/featured-articles/how-to-block-tor-the-onion-router/ta-p/177648" target="_blank"&gt;https://live.paloaltonetworks.com/t5/featured-articles/how-to-block-tor-the-onion-router/ta-p/177648&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 20:42:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336611#M84804</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-07-04T20:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336614#M84805</link>
      <description>&lt;P&gt;Thanks MP18&amp;nbsp; and&amp;nbsp; Vsys_remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know how to write policy from untrust to trust zone and what would be the source address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Trust to untrust Zone&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TOR.png" style="width: 798px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26581i695B323058878609/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="TOR.png" alt="TOR.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 01:06:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336614#M84805</guid>
      <dc:creator>Yusuf_PA</dc:creator>
      <dc:date>2020-07-05T01:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336616#M84806</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;do you mean when there is a TOR node behind the paloalto firewall that is publicly available?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Yes i mean this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 02:20:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336616#M84806</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-05T02:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336617#M84807</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135703"&gt;@Yusuf_PA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any web servers which are public facing?&lt;/P&gt;
&lt;P&gt;IF yes then you need security policy from untrust having source address as any to the public ip of web servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source Zone Untrust&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Destination Zone&amp;nbsp; - Where your web servers reside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be careful when you do this as we do not know your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 02:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336617#M84807</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-05T02:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336618#M84808</link>
      <description>&lt;P&gt;Thanks MP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While writing security policy from zone untrust to trust can we take source address&amp;nbsp;EDL (External Dynamic List) instead of any.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The following web-server (&lt;/SPAN&gt;&lt;A href="https://panwdbl.appspot.com/lists/ettor.txt" target="_blank" rel="noopener"&gt;https://panwdbl.appspot.com/lists/ettor.txt&lt;/A&gt;&lt;SPAN&gt;) contains a list of Tor exit nodes.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 03:20:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336618#M84808</guid>
      <dc:creator>Yusuf_PA</dc:creator>
      <dc:date>2020-07-05T03:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336668#M84838</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135703"&gt;@Yusuf_PA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes you can use the source address of EDL instead of any then destination address is whatever you want to protect in you network&lt;/P&gt;
&lt;P&gt;like servers etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 13:34:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336668#M84838</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-06T13:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336754#M84868</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Another thing I would add are additional policies that block on Application detection. That way if there are new TOR exit nodes and you dont have the changes, you'll still block the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1594067916021.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26604i6108F6A73E608339/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1594067916021.png" alt="OtakarKlier_0-1594067916021.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 20:38:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/336754#M84868</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-07-06T20:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor application traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/339462#M85240</link>
      <description>&lt;P&gt;Thanks MP18,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try the same as you mentioned.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 09:10:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-tor-application-traffic/m-p/339462#M85240</guid>
      <dc:creator>Yusuf_PA</dc:creator>
      <dc:date>2020-07-19T09:10:10Z</dc:date>
    </item>
  </channel>
</rss>

