<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Policy Action Options other than Allow/Deny in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12159#M8915</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, we can configure the rule by user or group, however it may not be a good idea to allow some users to override our company policy. We want the users can override some blocked applications when needed but at the same time system can log this action or admin can be alerted. I think it is more flexible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know many other brands FW with application control on the market can configure security rule as 'override' or 'alert'. If at the moment this option is not available on PAN device, I suggest adding this feature in the future release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Feb 2012 02:06:32 GMT</pubDate>
    <dc:creator>linuss</dc:creator>
    <dc:date>2012-02-17T02:06:32Z</dc:date>
    <item>
      <title>Security Policy Action Options other than Allow/Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12154#M8910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;We have a security rule:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Src Zone: Internal&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Src User: Any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Dest Zone: Any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Dest Add: Any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Application: Application filter which inlucde all online videos (e.g. adobe-media-player, http-video, tvb-video, youtube-base)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Action: Deny&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;It works as expected, however some users need to view some business video now. Is there any option to configure 'override' as action in security? &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;I found 'override' action can be selected in URL Filtering profile, here is part of admin guide:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Override&lt;/SPAN&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;mso-fareast-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt; - Allow the user to access the blocked page after entering a password. The password and other override settings are specified in the URL Admin Override area of the Settings page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;If override is not available, any option to allow users to watch video based on Frequency? Let say 3 hours per day? &lt;SPAN style="mso-spacerun:yes"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 09:17:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12154#M8910</guid>
      <dc:creator>linuss</dc:creator>
      <dc:date>2012-02-16T09:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Action Options other than Allow/Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12155#M8911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Override &amp;amp; Continue actions are URL filtering actions as you have found and they are not available under the security rule's action.&amp;nbsp; We do not classify recreational vs.business video apps, but web sites are classified by URL filtering categories.&amp;nbsp;&amp;nbsp; Hence, we can choose URL categories to override/continue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A suggestion is to control which URL categories users/groups are allowed/denied.&amp;nbsp; If they are given access to business web sites, they can access business videos from those sites.&amp;nbsp; Then apply override/continue actions to streaming-media category and apply a QoS policy to control the bandwidth for streaming media.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, there is the option to specify time-of-day where the policy is enforced under security rule.&amp;nbsp; You can block youtube, netflix from 8am-5pm while allowing them after hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 14:31:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12155#M8911</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-16T14:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Action Options other than Allow/Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12156#M8912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/people/rmonvon" id="jive-235741,171,773,951,181,334"&gt;rmonvon&lt;/A&gt;, thank you for your advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;URL filtering is not a perfect solution for our case. Because the "business" videos are uploaded to youtube by vendors, e.g. &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.youtube.com/watch?v=TTTbzbiBFfM&amp;amp;list=PL77D49394B6A8FD31&amp;amp;feature=plcp&amp;amp;context=C38c0451FDOEgsToPDskKoh7mooOkmGNbGHjL4-Ecx"&gt;http://www.youtube.com/watch?v=TTTbzbiBFfM&amp;amp;list=PL77D49394B6A8FD31&amp;amp;feature=plcp&amp;amp;context=C38c0451FDOEgsToPDskKoh7mooOkmGNbGHjL4-Ecx&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 17:18:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12156#M8912</guid>
      <dc:creator>linuss</dc:creator>
      <dc:date>2012-02-16T17:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Action Options other than Allow/Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12157#M8913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, youtube only classifies materials that are inappropriate for childrens.&amp;nbsp; It does not classify contents as business, health-medicine, etc to filter on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 17:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12157#M8913</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-16T17:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Action Options other than Allow/Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12158#M8914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you specify somehow who these users are?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like by srcip or by srcuser (AD integration)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since PAN is top-down first-match you could add a rule similar to following just before your current rule to take care of the users who should be able to view online videos:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Src Zone: Internal&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Src User: USER_Video_Allowed&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Dest Zone: Any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Dest Add: Any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Application: Application filter which inlucde all online videos (e.g. adobe-media-player, http-video, tvb-video, youtube-base)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; line-height:normal"&gt;&lt;SPAN style="font-size:12.0pt;font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;;mso-fareast-language:ZH-TW"&gt;Action: Allow&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 21:07:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12158#M8914</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-16T21:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Action Options other than Allow/Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12159#M8915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, we can configure the rule by user or group, however it may not be a good idea to allow some users to override our company policy. We want the users can override some blocked applications when needed but at the same time system can log this action or admin can be alerted. I think it is more flexible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know many other brands FW with application control on the market can configure security rule as 'override' or 'alert'. If at the moment this option is not available on PAN device, I suggest adding this feature in the future release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 02:06:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12159#M8915</guid>
      <dc:creator>linuss</dc:creator>
      <dc:date>2012-02-17T02:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Action Options other than Allow/Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12160#M8916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both continue and block is available in PAN since years.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just add the custom rule as I described but use a custom security profile where you define that the url category (or all categories for that matter) will result in a continue. This way you will decide through appid which apps should get the continuepage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also select a url profile straigth away from the security rule view but I prefer to bundle stuff into security profiles but thats just a matter of taste.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 03:37:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-action-options-other-than-allow-deny/m-p/12160#M8916</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-17T03:37:47Z</dc:date>
    </item>
  </channel>
</rss>

