<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to block exe files after using File blocking Profile in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354822#M87471</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are a few tips I hope will help:&lt;/P&gt;&lt;P&gt;1. In the blocking profile put EXE &amp;amp; PE together (portable-executable), direction=download, action=block, application=any (test then change as needed) make sure this is the only rule in the file blocking profile, or the top rule if other file blocking-alert rules exist.&lt;/P&gt;&lt;P&gt;2. Try to use a non-https protocol either FTP or HTTP as HTTPS will require you to use SSL decryption that you did not state if you were using or not.&lt;/P&gt;&lt;P&gt;3. I assume you checked traffic was hitting the rule that has this profile attached to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2020 11:19:58 GMT</pubDate>
    <dc:creator>ShaiW</dc:creator>
    <dc:date>2020-10-07T11:19:58Z</dc:date>
    <item>
      <title>unable to block exe files after using File blocking Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354790#M87468</link>
      <description>&lt;P&gt;I have followed&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/set-up-file-blocking" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/set-up-file-blocking&lt;/A&gt;&amp;nbsp;and created a file blocking profile to block Downloads of exe format while browsing. But it still does not block the exe downloads on the server i applied the file blocking profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check&amp;nbsp; and suggest the fix.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 10:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354790#M87468</guid>
      <dc:creator>AnupAllam</dc:creator>
      <dc:date>2020-10-07T10:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: unable to block exe files after using File blocking Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354822#M87471</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are a few tips I hope will help:&lt;/P&gt;&lt;P&gt;1. In the blocking profile put EXE &amp;amp; PE together (portable-executable), direction=download, action=block, application=any (test then change as needed) make sure this is the only rule in the file blocking profile, or the top rule if other file blocking-alert rules exist.&lt;/P&gt;&lt;P&gt;2. Try to use a non-https protocol either FTP or HTTP as HTTPS will require you to use SSL decryption that you did not state if you were using or not.&lt;/P&gt;&lt;P&gt;3. I assume you checked traffic was hitting the rule that has this profile attached to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 11:19:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354822#M87471</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2020-10-07T11:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: unable to block exe files after using File blocking Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354826#M87472</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;ShaiW,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L3-Networker lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Thanks for the Quick Reply.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L3-Networker lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;1.Yes i made sure file blocking profile is created as suggested.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Blockexe.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28129i69B33650E4BA50C3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Blockexe.PNG" alt="Blockexe.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The requirement in general we want is that all our users to be blocked from downloading install files like .exe files when they do browsing from internet - so please suggest how to setup&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;SSL decryption if that is needed to achieve for HTTPS as well.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As of we have a Decryption Profile enabled, but i see that under -&amp;gt;SSL Decryption - -No options are selected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Decryption Profile.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28130iEF56E8FA89CBE8F9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Decryption Profile.PNG" alt="Decryption Profile.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. Yes I checked that the traffic&amp;nbsp;is hitting the rule that this profile is attached and result is allowed and nothing is getting blocked as of now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please let me know if you need me to check anything else.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note: I'm&amp;nbsp;a Newbie to Palo Alto, so please excuse my knowledge.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anup&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 12:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354826#M87472</guid>
      <dc:creator>AnupAllam</dc:creator>
      <dc:date>2020-10-07T12:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: unable to block exe files after using File blocking Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354863#M87476</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158224"&gt;@AnupAllam&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;There's a lot of documents surrounding setting up SSL Decryption, I'll link a few of them below. The screenshot that you posted just says that you aren't following best practice on the profile, but decryption would actually be "activated" so to speak by setting up a Decryption rulebase policy. You'll definitely want to read up on that prior to activating it; there's client changes you'll need to make so they don't get security warnings and potential legal requirements depending on what regulatory bodies you may fall under and local laws.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The second link has a video that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;made that walks you through the process of getting this setup.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEZCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEZCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmyCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmyCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 15:02:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/354863#M87476</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-07T15:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: unable to block exe files after using File blocking Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/355008#M87503</link>
      <description>&lt;P&gt;Hi Pry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually this is Non-Prod, so we dont have any users- hence will&amp;nbsp; not affect anybody,&amp;nbsp; I am&amp;nbsp; the User who will&amp;nbsp; test the file blocking.&lt;/P&gt;&lt;P&gt;I am going through the documents you send, will&amp;nbsp; update if any of the settings work to help me block the exe files.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 03:29:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/355008#M87503</guid>
      <dc:creator>AnupAllam</dc:creator>
      <dc:date>2020-10-08T03:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: unable to block exe files after using File blocking Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/355010#M87505</link>
      <description>&lt;P&gt;I tried enabling various options under the Decrypt Profile - SSL Decryption and commit it, But no Luck still cant block the exe files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The website that I'm testing to download exe file is from&amp;nbsp;&lt;A href="https://www.7-zip.org/download.html" target="_blank"&gt;https://www.7-zip.org/download.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me fix the issue and let me know what other options do i need to add to get this File Blocking working.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 03:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/355010#M87505</guid>
      <dc:creator>AnupAllam</dc:creator>
      <dc:date>2020-10-08T03:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: unable to block exe files after using File blocking Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/355042#M87511</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of the items in the Objects tab &lt;U&gt;do not have any affect&lt;/U&gt; on traffic if they are not attached to Policies. This includes Decryption Profile/s.&lt;/P&gt;&lt;P&gt;1. So - the File Blocking (FB) Profile must be attached to a security rule.&lt;/P&gt;&lt;P&gt;2. I highly recommend splitting your issue into two parts, get FB working then tackle Decryption. For FB I would recommend you try to download this test file from Palo Alto as it uses the HTTP protocol hence no need for decryption, yet.&lt;/P&gt;&lt;P&gt;&lt;A href="http://wildfire.paloaltonetworks.com/publicapi/test/pe" target="_blank" rel="noopener"&gt;http://wildfire.paloaltonetworks.com/publicapi/test/pe&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(This is an anti-virus test file, it will probably get blocked by AV software but it does not matter as all we want is for it to download or get blocked by the filewall)&lt;/P&gt;&lt;P&gt;If you see it blocked and logged under Monitor-&amp;gt; Data Filtering - it means FB is working for non-encrypted traffic. Continue to enable Decryption:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. For Decryption you really should read the above mentioned articles and notes by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;as enabling it requires:&lt;/P&gt;&lt;P&gt;3a. Generating Decryption Certificates on the firewall, self-signed for testing or Corporate CA signed (much preferred)&lt;/P&gt;&lt;P&gt;3b. Having them in all computers, trusted root certificate store&lt;/P&gt;&lt;P&gt;3c. Creating a Decryption Policy under Policies-&amp;gt;Decryption: for testing start with:&lt;/P&gt;&lt;P&gt;Source Zone Internal (or whatever you named it)&lt;/P&gt;&lt;P&gt;Dest Zone External (or whatever you named it)&lt;/P&gt;&lt;P&gt;Service: service_http + service_https&lt;/P&gt;&lt;P&gt;Action: Decrypt&lt;/P&gt;&lt;P&gt;Type: SSL Forward Proxy&lt;/P&gt;&lt;P&gt;Decryption Profile: is optional&lt;/P&gt;&lt;P&gt;3d. In some older PANOS versions you must also allow in Security rules Application=web-browsing &amp;amp; service=service_https (this is not the default, hence needs adding).&lt;/P&gt;&lt;P&gt;* This might look like easy 4 steps but trust me - it isn't.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, log into the learning center at:&lt;/P&gt;&lt;P&gt;&lt;A href="http://education.paloaltonetworks.com/learningcenter" target="_blank" rel="noopener"&gt;http://education.paloaltonetworks.com/learningcenter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Search for EDU-110, register for it for free and start watching this online training about the NGFW, but note that the training center is being moved you might be redirected to the new training site in a few days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 05:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/355042#M87511</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2020-10-08T05:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: unable to block exe files after using File blocking Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/355072#M87515</link>
      <description>&lt;P&gt;Hi Shai,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you, The File Blocking worked once i removed the SSL Decryption and tested it with the http protocol site you gave&amp;nbsp;&lt;A href="http://wildfire.paloaltonetworks.com/publicapi/test/pe" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;http://wildfire.paloaltonetworks.com/publicapi/test/pe&lt;/A&gt;&amp;nbsp;. But now how do i apply the same for https sites ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FileBlockSuccess.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28137i63AA7D25E94B1F91/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="FileBlockSuccess.PNG" alt="FileBlockSuccess.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like you said in Step 3,&amp;nbsp; I need to figure out how to &lt;SPAN&gt;enable Decryption as it does not look easy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 08:13:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-block-exe-files-after-using-file-blocking-profile/m-p/355072#M87515</guid>
      <dc:creator>AnupAllam</dc:creator>
      <dc:date>2020-10-08T08:13:54Z</dc:date>
    </item>
  </channel>
</rss>

