<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tips to block Yahoo Mail but not other parts of Yahoo in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tips-to-block-yahoo-mail-but-not-other-parts-of-yahoo/m-p/396293#M91356</link>
    <description>&lt;P&gt;I have not seen such issue before. So the because the SSL decrypton does not work always the the App-ID does not match correctly the yahoo app-id (Because of this App-ID "SSL" instead of "yahoo-mail-base." maybe the SSL decryption is not happening)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you focused on why the SSL decryption does not work every time:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/decryption-features/enhanced-ssl-decryption-troubleshooting.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/decryption-features/enhanced-ssl-decryption-troubleshooting.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloUCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloUCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also maybe when the users have accessed the yahoo and when they access it a second time a "secure renegotiation" is triggered and not a full handshake and maybe this causes the firewall not to be able to decrypt the traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/td-p/27979" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/td-p/27979&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POJ0CAO&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POJ0CAO&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If SSL decryption is the issue test using a Decryption profile to try to stop this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-decryption-profile/settings-to-control-decrypted-ssl-traffic.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-decryption-profile/settings-to-control-decrypted-ssl-traffic.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the ssl decryption is ok but the issue is with the app-id wrongly watching then better wait for the TAC to fix their APP-ID.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Apr 2021 10:23:32 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2021-04-07T10:23:32Z</dc:date>
    <item>
      <title>Tips to block Yahoo Mail but not other parts of Yahoo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tips-to-block-yahoo-mail-but-not-other-parts-of-yahoo/m-p/396040#M91336</link>
      <description>&lt;P&gt;I wanted to make a post to the community to see what other people are doing about this issue.&amp;nbsp; We currently have a support case open with Palo for this and has been open for quite some time.&amp;nbsp; Long story short, users that have previously logged into a Yahoo account and have a session cookie are able to somehow circumvent security policy and the app sometimes is parsed as App-ID "SSL" instead of "yahoo-mail-base."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are able to recreate this behavior 100% of the time.&amp;nbsp; The only way we were able to block Yahoo Mail was by selectively decrypting this traffic and blocking the following URL's:&lt;/P&gt;&lt;P&gt;mail.yahoo.com&lt;BR /&gt;login.yahoo.com&lt;/P&gt;&lt;P&gt;*.mail.yahoo.com&lt;/P&gt;&lt;P&gt;*.login.yahoo.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even with the decryption applied, the sessions are still sometimes getting misparsed and users are still able to access Yahoo Mail.&amp;nbsp; Again, this is directly related to if the user has logged into a Yahoo account before or not; if the person has never previously logged into a Yahoo account, the access is blocked completely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now since "login.yahoo.com" is on this URL category we created, users are unable to login to Yahoo for other areas (such as Yahoo Finance).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just seeing if the community has tackled this issue before why we keep trying through traditional support channels.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 14:48:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tips-to-block-yahoo-mail-but-not-other-parts-of-yahoo/m-p/396040#M91336</guid>
      <dc:creator>tszafa</dc:creator>
      <dc:date>2021-04-06T14:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Tips to block Yahoo Mail but not other parts of Yahoo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tips-to-block-yahoo-mail-but-not-other-parts-of-yahoo/m-p/396293#M91356</link>
      <description>&lt;P&gt;I have not seen such issue before. So the because the SSL decrypton does not work always the the App-ID does not match correctly the yahoo app-id (Because of this App-ID "SSL" instead of "yahoo-mail-base." maybe the SSL decryption is not happening)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you focused on why the SSL decryption does not work every time:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/decryption-features/enhanced-ssl-decryption-troubleshooting.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/decryption-features/enhanced-ssl-decryption-troubleshooting.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloUCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloUCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also maybe when the users have accessed the yahoo and when they access it a second time a "secure renegotiation" is triggered and not a full handshake and maybe this causes the firewall not to be able to decrypt the traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/td-p/27979" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/td-p/27979&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POJ0CAO&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POJ0CAO&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If SSL decryption is the issue test using a Decryption profile to try to stop this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-decryption-profile/settings-to-control-decrypted-ssl-traffic.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-decryption-profile/settings-to-control-decrypted-ssl-traffic.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the ssl decryption is ok but the issue is with the app-id wrongly watching then better wait for the TAC to fix their APP-ID.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 10:23:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tips-to-block-yahoo-mail-but-not-other-parts-of-yahoo/m-p/396293#M91356</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-04-07T10:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tips to block Yahoo Mail but not other parts of Yahoo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tips-to-block-yahoo-mail-but-not-other-parts-of-yahoo/m-p/396692#M91400</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would recommend setting the URL category&amp;nbsp;Web-based Email to block. This way you dont need to mess with custom block url's etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also as mentioned SSL decryption should be enabled, however a lot of URL traffic can be blocked like this since its in the plain text part of the packet.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 21:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tips-to-block-yahoo-mail-but-not-other-parts-of-yahoo/m-p/396692#M91400</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-04-08T21:38:31Z</dc:date>
    </item>
  </channel>
</rss>

