<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Blocking feature not working with owncloud-uploading application hosted on NGINX web server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-feature-not-working-with-owncloud-uploading/m-p/360305#M88083</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61214"&gt;@grenzi&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the session details, can you see if the sessions are actually decrypted successfully ? Just thinking out loud here ... do you allow the session if decryption fails ?&lt;/P&gt;&lt;P&gt;Are you seeing the same behaviour in both PAN-OS 10.0 and 9.0 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheersm&lt;/P&gt;&lt;P&gt;-Kiwi.&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I just figured it out that this behavior could be related to HTTP2. After disabling HTTP2 on the NGINX server, files are correctly blocked in upload as expected. I also found that decryption doesn't work on 9.0 and 9.1 with HTTP2, while in 10.0 it does. I think I have to deepen on how HTTP2 works and why the firewall is unable to detect file uploads while it correctly detects dowloads.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Nov 2020 17:43:05 GMT</pubDate>
    <dc:creator>grenzi</dc:creator>
    <dc:date>2020-11-02T17:43:05Z</dc:date>
    <item>
      <title>File Blocking feature not working with owncloud-uploading application hosted on NGINX web server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-feature-not-working-with-owncloud-uploading/m-p/359593#M87997</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; the thread subject is pretty self explanatory. I'm playing with the file-blocking feature and doing some testing. What I've found in my lab environment, using both PAN-OS 10.0.1 and PAN-OS 9.0.9 and both VM-Series an PA-820 appliance, is that file blocking is not always working with application owncloud-uploading.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a file-blocking profile configured to block pdf, exe and msi files in both directions (upload and download) and this is what I just found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**Scenario 1**&lt;/P&gt;&lt;P&gt;Web server: Apache 2.4&lt;/P&gt;&lt;P&gt;Application: Nextcloud 19.0.4&lt;/P&gt;&lt;P&gt;Server architecture: x86-64&lt;/P&gt;&lt;P&gt;PHP: php-fpm&lt;/P&gt;&lt;P&gt;SSL forward proxy: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenario 2&lt;/P&gt;&lt;P&gt;WebServer: NGINX 1.19&lt;/P&gt;&lt;P&gt;Application: Nextcloud 19.0.4&lt;/P&gt;&lt;P&gt;Server architecture: ARM&lt;/P&gt;&lt;P&gt;PHP: php-fpm&lt;/P&gt;&lt;P&gt;SSL forward proxy: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Scenario 1, if I try to upload or download any of the blocked file types, the firewall correctly denies the session as expected and logs the event into the data filtering logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Scenario 2, if I try to download any of the blocked file types, the firewalls denies the session as expected, but if I try to upload the file the firewall permits the session and the upload is successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea on how to investigate deeper into this issue? I will update this thread as soon I have time to try other web application on a NGINX web server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 11:48:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-feature-not-working-with-owncloud-uploading/m-p/359593#M87997</guid>
      <dc:creator>grenzi</dc:creator>
      <dc:date>2020-10-29T11:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: File Blocking feature not working with owncloud-uploading application hosted on NGINX web server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-feature-not-working-with-owncloud-uploading/m-p/360263#M88078</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61214"&gt;@grenzi&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking at the session details, can you see if the sessions are actually decrypted successfully ? Just thinking out loud here ... do you allow the session if decryption fails ?&lt;/P&gt;
&lt;P&gt;Are you seeing the same behaviour in both PAN-OS 10.0 and 9.0 ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheersm&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 02 Nov 2020 14:42:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-feature-not-working-with-owncloud-uploading/m-p/360263#M88078</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-11-02T14:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: File Blocking feature not working with owncloud-uploading application hosted on NGINX web server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-feature-not-working-with-owncloud-uploading/m-p/360305#M88083</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61214"&gt;@grenzi&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the session details, can you see if the sessions are actually decrypted successfully ? Just thinking out loud here ... do you allow the session if decryption fails ?&lt;/P&gt;&lt;P&gt;Are you seeing the same behaviour in both PAN-OS 10.0 and 9.0 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheersm&lt;/P&gt;&lt;P&gt;-Kiwi.&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I just figured it out that this behavior could be related to HTTP2. After disabling HTTP2 on the NGINX server, files are correctly blocked in upload as expected. I also found that decryption doesn't work on 9.0 and 9.1 with HTTP2, while in 10.0 it does. I think I have to deepen on how HTTP2 works and why the firewall is unable to detect file uploads while it correctly detects dowloads.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 17:43:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-feature-not-working-with-owncloud-uploading/m-p/360305#M88083</guid>
      <dc:creator>grenzi</dc:creator>
      <dc:date>2020-11-02T17:43:05Z</dc:date>
    </item>
  </channel>
</rss>

