<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wetransfer download site we.tl not seen as Wetransfer application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/400915#M91642</link>
    <description>&lt;P&gt;I have created a rule which allow the wetransfer (download and upload) application.&lt;/P&gt;&lt;P&gt;But when a user receive an email to download a file the url is we.tl/random numbers.&lt;/P&gt;&lt;P&gt;When the user clicks it the firewall doesn't see it as the application wetransfer-download but as category online storage and backup.&lt;/P&gt;&lt;P&gt;Is this a bug in the Pan-OS and how can we solve this?&lt;/P&gt;</description>
    <pubDate>Wed, 21 Apr 2021 13:29:29 GMT</pubDate>
    <dc:creator>ZEBIT</dc:creator>
    <dc:date>2021-04-21T13:29:29Z</dc:date>
    <item>
      <title>Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/400915#M91642</link>
      <description>&lt;P&gt;I have created a rule which allow the wetransfer (download and upload) application.&lt;/P&gt;&lt;P&gt;But when a user receive an email to download a file the url is we.tl/random numbers.&lt;/P&gt;&lt;P&gt;When the user clicks it the firewall doesn't see it as the application wetransfer-download but as category online storage and backup.&lt;/P&gt;&lt;P&gt;Is this a bug in the Pan-OS and how can we solve this?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 13:29:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/400915#M91642</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2021-04-21T13:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/400941#M91646</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1006"&gt;@ZEBIT&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I don't use Wetransfer so I can't speak to the accuracy of the App-ID, but just to confirm, are you decrypting the traffic? If you are and it's still not registering properly, you can submit it to TAC to request the existing ID be modified to capture the traffic properly.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 14:44:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/400941#M91646</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-04-21T14:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/401224#M91671</link>
      <description>&lt;P&gt;Yeah we are decrypting the traffic. But doesn't get recognized as the correct app-id.&lt;/P&gt;&lt;P&gt;The link that get's opened is&amp;nbsp;download.wetransfer.com/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that the app-id is wetransfer downloading which is allowed, but the url download.wetransfer.com is in the URL categorie online backup and storage and that is a block categorie in our environment. So one rule is over rulling the other one.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 12:09:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/401224#M91671</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2021-04-22T12:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/401280#M91680</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1006"&gt;@ZEBIT&lt;/a&gt;&amp;nbsp;so the app-id is getting recorded correctly, or it isn't? You are likely just running into an order of operations issue honestly. IE: If you are blocking the URL category the firewall may not be able to classify the traffic properly before the traffic is identified as online backup and storage and dropped by whatever rule you have denying that traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 14:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/401280#M91680</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-04-22T14:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/401461#M91706</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; I have rules which allows app like wetransfer download and no URL filtering. After this rule I have a rule with URL filtering.&lt;/P&gt;&lt;P&gt;When we we hit the site download.wetransfer.com the app rule doesn't get hit but the URL filtering rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After allowing the category online storage and backup the site get recognized as wetransfer-download.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 07:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/401461#M91706</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2021-04-23T07:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/401538#M91720</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1006"&gt;@ZEBIT&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I would say the problem is not with the app-id signature, but how networks work...&lt;/P&gt;&lt;P&gt;When you visit the download page and browser create new HTTP connection firewall will first see the TCP connection, then the SSL neogtiation and only after that the actual data. As you can imagine FW need some amount of packets to pass in order to categorize the application. So even that your wetransfer app rule is above, for the first couple of packets FW will not match this rule (because it will identify it as application = web-browsing/ssl), so it will match our generic web browsing rule (the one with url filtering).&lt;/P&gt;&lt;P&gt;FW will be able to categorize the URL and therefore take the action base on your url filtering profile. If it is allowed more traffic will start passing over the FW so the app-id engine will have enough data to detect that it is actually wetranfer and not the generic web-browsing. In that moment FW will make another policy lookup (because the app has changes) and now it will match your wetransfer specific rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess you can try to submit request for app optimisation so the wetransfer app signature match earlier (but not sure if that is possible)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you could do is:&lt;/P&gt;&lt;P&gt;- Create custom URL category and add wetransfer domain (with wildcard or specific subdomains you choose)&lt;/P&gt;&lt;P&gt;- Go to your URL filtering profile and choose alert/allow for the category you create above&lt;/P&gt;&lt;P&gt;This will create whitelist only for the wetransfer while you still block "online storage and backup" category&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 15:58:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/401538#M91720</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-04-23T15:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/405030#M91967</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1006"&gt;@ZEBIT&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Have you found a solution to this problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 19:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/405030#M91967</guid>
      <dc:creator>QuentinH</dc:creator>
      <dc:date>2021-05-05T19:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/405107#M91972</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176706"&gt;@QuentinH&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah we found a solution.&lt;/P&gt;&lt;P&gt;We created an application group with the file sharing apps we allow. This is wetransfer and google drive.&lt;/P&gt;&lt;P&gt;After that I created a policy rule called File sharing app, allowed the users who may use these apps, set the Application to the application group we created and in the URL filtering we allowed the category online storage and backup. We created a seperate URL filtering for this policy rule.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 08:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/405107#M91972</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2021-05-06T08:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/405137#M91974</link>
      <description>&lt;P&gt;hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1006"&gt;@ZEBIT&lt;/a&gt;&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;So you allowed the "Online-storage-and-backup" category?&lt;BR /&gt;Then you have created a rule to allow wetransfer upload urls or you have created a rule to block download urls,&lt;/P&gt;&lt;P&gt;Please can you describe the process you used?&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 07:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/405137#M91974</guid>
      <dc:creator>QuentinH</dc:creator>
      <dc:date>2021-05-06T07:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Wetransfer download site we.tl not seen as Wetransfer application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/405165#M91975</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176706" target="_blank"&gt;@QuentinH&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah we found a solution.&lt;/P&gt;&lt;P&gt;We created an application group with the file sharing apps we allow. This is wetransfer and google drive.&lt;/P&gt;&lt;P&gt;After that I created a policy rule called File sharing app, allowed the users who may use these apps, set the Application to the application group we created and in the URL filtering we allowed the category online storage and backup. We created a seperate URL filtering for this policy rule.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 08:38:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wetransfer-download-site-we-tl-not-seen-as-wetransfer/m-p/405165#M91975</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2021-05-06T08:38:19Z</dc:date>
    </item>
  </channel>
</rss>

