<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File blocking for allowing specific file type to be download. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-for-allowing-specific-file-type-to-be-download/m-p/395969#M91326</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167254"&gt;@Vijaygvasan&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your suggestion to decrypt the traffic is the way to go in my humble opinion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm afraid that without a decryption policy, file blocking just won't do a decent job.&amp;nbsp; You won't have any visibility inside any HTTPS traffic and you won't be able to block anything using file blocking this way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't want to use a decryption policy then I suggest that you use some form of endpoint protection (Cortex XDR ?) but I'm not sure it allows for the same granularity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 06 Apr 2021 08:53:11 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2021-04-06T08:53:11Z</dc:date>
    <item>
      <title>File blocking for allowing specific file type to be download.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-for-allowing-specific-file-type-to-be-download/m-p/395638#M91295</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have query regarding fileblocking where i just want to allow certain type of file to be downloaded and uploaded for specific file type. So for example. im allowing exe extension for microsoft.com and i provided the option to alert. And when i first made a request for the webpage it works as expected. But when i tried request for different website i did get the response page from that website as well. And im also able to see that the exe file gets to be downloaded on different website. So i created a deny rule for blocking exe for any destination. But still im able to see that i could download the files on different website.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My suggestion was to go with Decrypting the traffic and making those who need to download can have access for that. But i just need all your inputs to do this without decrypting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached is the allow for the traffic and the second one is deny on the file blocking profile.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Apr 2021 04:34:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-for-allowing-specific-file-type-to-be-download/m-p/395638#M91295</guid>
      <dc:creator>Vijaygvasan</dc:creator>
      <dc:date>2021-04-03T04:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking for allowing specific file type to be download.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-for-allowing-specific-file-type-to-be-download/m-p/395969#M91326</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167254"&gt;@Vijaygvasan&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your suggestion to decrypt the traffic is the way to go in my humble opinion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm afraid that without a decryption policy, file blocking just won't do a decent job.&amp;nbsp; You won't have any visibility inside any HTTPS traffic and you won't be able to block anything using file blocking this way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't want to use a decryption policy then I suggest that you use some form of endpoint protection (Cortex XDR ?) but I'm not sure it allows for the same granularity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Apr 2021 08:53:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-for-allowing-specific-file-type-to-be-download/m-p/395969#M91326</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-04-06T08:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: File blocking for allowing specific file type to be download.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-for-allowing-specific-file-type-to-be-download/m-p/395988#M91328</link>
      <description>&lt;P&gt;Thanks buddy, I have made the decryption policy anyways and im able to block and allow the traffic as intended. Also i could face a bit of slowness issue it takes more time than usual to load web pages. basic web browsing like yahoo, times of india, speed test etc. So will there be any option to check whether and why it takes long time.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 10:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-blocking-for-allowing-specific-file-type-to-be-download/m-p/395988#M91328</guid>
      <dc:creator>Vijaygvasan</dc:creator>
      <dc:date>2021-04-06T10:21:47Z</dc:date>
    </item>
  </channel>
</rss>

