<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help allowing .dll files for VPN users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-allowing-dll-files-for-vpn-users/m-p/342117#M85779</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like everyone, we have a lot of folks working from home. We use a CRM system called Ajeera, and in order to load up the various modules, the client system downloads an app from the server, which includes a .dll file. In the office, it works just fine, over VPN the .dll file is blocked. (It's a "ClickOnce" app, which is a new term to me, but it seems to be relevant)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm a little new to the firewall rules game, so I was hoping if someone could tell me if I'm on the right track. The model is PA-220, software is 9.0.9-h1. Nothing overly fancy about the setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new security policy, set the source as the server specifically (192.168.x.x./32), destination is VPN zone.&lt;/P&gt;&lt;P&gt;Added the group profile "internal", which includes the Internal FB security profile, which I see does not block .dll files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume I'll need to position this new policy above the policy that is blocking the .dll files. I've saved the config but not committed it. (Would this sort of change cause a reboot upon committing?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm obviously not looking for, "Hey, nice job, mate! You did it perfectly!" as there's tons of details missing.&amp;nbsp; Just wondering if my logic is sound.&amp;nbsp; Also wondering if committing will cause a reboot, that's not clear to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2020 00:18:21 GMT</pubDate>
    <dc:creator>10Thirteen</dc:creator>
    <dc:date>2020-08-05T00:18:21Z</dc:date>
    <item>
      <title>Help allowing .dll files for VPN users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-allowing-dll-files-for-vpn-users/m-p/342117#M85779</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like everyone, we have a lot of folks working from home. We use a CRM system called Ajeera, and in order to load up the various modules, the client system downloads an app from the server, which includes a .dll file. In the office, it works just fine, over VPN the .dll file is blocked. (It's a "ClickOnce" app, which is a new term to me, but it seems to be relevant)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm a little new to the firewall rules game, so I was hoping if someone could tell me if I'm on the right track. The model is PA-220, software is 9.0.9-h1. Nothing overly fancy about the setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new security policy, set the source as the server specifically (192.168.x.x./32), destination is VPN zone.&lt;/P&gt;&lt;P&gt;Added the group profile "internal", which includes the Internal FB security profile, which I see does not block .dll files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume I'll need to position this new policy above the policy that is blocking the .dll files. I've saved the config but not committed it. (Would this sort of change cause a reboot upon committing?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm obviously not looking for, "Hey, nice job, mate! You did it perfectly!" as there's tons of details missing.&amp;nbsp; Just wondering if my logic is sound.&amp;nbsp; Also wondering if committing will cause a reboot, that's not clear to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 00:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-allowing-dll-files-for-vpn-users/m-p/342117#M85779</guid>
      <dc:creator>10Thirteen</dc:creator>
      <dc:date>2020-08-05T00:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help allowing .dll files for VPN users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-allowing-dll-files-for-vpn-users/m-p/342208#M85794</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151215"&gt;@10Thirteen&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes that sounds about right.&lt;/P&gt;
&lt;P&gt;A commit should not trigger a reboot ... that said, I've seen cases where commits disrupted traffic and/or even disconnect VPNs.&amp;nbsp; So you might want to schedule this during a maintenance window.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 05 Aug 2020 13:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-allowing-dll-files-for-vpn-users/m-p/342208#M85794</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-08-05T13:56:37Z</dc:date>
    </item>
  </channel>
</rss>

