<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data copying over Global protect VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385949#M90186</link>
    <description>&lt;P&gt;ah yes RDP&lt;/P&gt;&lt;P&gt;Microsoft put in some nifty (and prorietary) encryption that prevents the firewall from blocking files being copied&lt;/P&gt;&lt;P&gt;you can, however, control which actions are allowed by users in the RDP configuration tself on the server, so you can push out Global Policies that prevent files from being copied when users are connected via RDP (and have users use SMB instead, which you can control)&lt;/P&gt;</description>
    <pubDate>Mon, 15 Feb 2021 13:13:30 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2021-02-15T13:13:30Z</dc:date>
    <item>
      <title>Data copying over Global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385853#M90173</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have one query:-&lt;/P&gt;&lt;P&gt;If, I am connected with GP VPN and. I want to prevent the users can not copy files or data from the shared folder and server.&lt;/P&gt;&lt;P&gt;is it possible?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 05:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385853#M90173</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-02-15T05:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Data copying over Global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385932#M90181</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes this is possible in multiple ways:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can restrict access via security rules or security profiles:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;in the security rules you could block access to a server completely (block rule),&lt;/LI&gt;&lt;LI&gt;or only allow certain applications. some applications are even split up in file sharing 'child' applications and other functionality, so you could allow some functionality but block file transfers&lt;/LI&gt;&lt;LI&gt;additionally you can add file blocking profiles that prevent some or all filetypes from being transmitted in one direction or both: you could set up a security rule that allows a file transfer application, but then add a security profile (file blocking profile) that only allows uploads and blocks downloads&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 15 Feb 2021 12:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385932#M90181</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-15T12:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Data copying over Global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385944#M90184</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P&gt;First of all, i can not block completely server access. i need to block only copy files from the server or to the server.&lt;/P&gt;&lt;P&gt;I have tried to block the copy file by the file blocking profile but still i am able to copy file via VPN.&lt;/P&gt;&lt;P&gt;Below is the configuration description that I already tried.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File blocking profile:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1613393336891.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29932i5876BFE46E1B9284/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1613393336891.png" alt="Jafar_Hussain_0-1613393336891.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security rule:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source zone - GP zone, inside zone&lt;/P&gt;&lt;P&gt;user - any&lt;/P&gt;&lt;P&gt;Source address Address - Any&lt;/P&gt;&lt;P&gt;Destination Zone - GP zone, Inside zone&lt;/P&gt;&lt;P&gt;Application - ms-rdp&lt;/P&gt;&lt;P&gt;Service - Any&lt;/P&gt;&lt;P&gt;Action - Allow&lt;/P&gt;&lt;P&gt;Profile - File blocking test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This scenario i tried but unable to block.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 12:52:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385944#M90184</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-02-15T12:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: Data copying over Global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385949#M90186</link>
      <description>&lt;P&gt;ah yes RDP&lt;/P&gt;&lt;P&gt;Microsoft put in some nifty (and prorietary) encryption that prevents the firewall from blocking files being copied&lt;/P&gt;&lt;P&gt;you can, however, control which actions are allowed by users in the RDP configuration tself on the server, so you can push out Global Policies that prevent files from being copied when users are connected via RDP (and have users use SMB instead, which you can control)&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 13:13:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385949#M90186</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-15T13:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Data copying over Global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385950#M90187</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per my understanding, you are saying we need to block only smb application from the Paloalto?&lt;/P&gt;&lt;P&gt;Mainly, we need to prevent users from copying files from shared folders to their systems when they access through VPN. Also, i want to know, how to do that for access over RDP.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 13:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385950#M90187</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-02-15T13:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Data copying over Global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385960#M90189</link>
      <description>&lt;P&gt;no: you can't block file transfer via RDP in the firewall because microsoft built in an encryption that can't be deciphered by the firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it IS possible to disable filetransfer through RDP via GPO :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://social.technet.microsoft.com/Forums/en-US/f07b2557-27fd-484f-9a62-635057959214/disable-file-transfercopy-paste-for-rds?forum=winserverTS" target="_blank"&gt;https://social.technet.microsoft.com/Forums/en-US/f07b2557-27fd-484f-9a62-635057959214/disable-file-transfercopy-paste-for-rds?forum=winserverTS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 14:30:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-copying-over-global-protect-vpn/m-p/385960#M90189</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-15T14:30:58Z</dc:date>
    </item>
  </channel>
</rss>

