<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Want to block personal gmail and allow corporated gmail in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440373#M99886</link>
    <description>&lt;P&gt;Indeed, historically this is accomplished through HTTP header insertion described above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An alternative method would be the new &lt;A href="https://docs.paloaltonetworks.com/saas-security/saas-security-admin/saas-security-inline/get-started-with-saas-security-inline/whats-saas-security-inline.html" target="_self"&gt;SaaS Security Inline subscription&lt;/A&gt;, some of my customers opt for the latter as it's much easier to configure and manage.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Oct 2021 20:20:14 GMT</pubDate>
    <dc:creator>LAYER_8</dc:creator>
    <dc:date>2021-10-12T20:20:14Z</dc:date>
    <item>
      <title>Want to block personal gmail and allow corporated gmail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440243#M99878</link>
      <description>&lt;P&gt;Hey guys one of my customer wants to block personal gmail (google mail) for eg : &lt;A href="mailto:example@gmail.com" target="_blank"&gt;example@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and want to allow the corporate Gmail eg : &lt;A href="mailto:example@corporate.com" target="_blank"&gt;example@corporate.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what are the steps to configure this type of request please help us.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 11:31:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440243#M99878</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-10-12T11:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Want to block personal gmail and allow corporated gmail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440293#M99883</link>
      <description>&lt;P&gt;You need to TLS intercept the traffic, downgrade it from HTTP/2 and then insert a header. There are instructions at&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/http-header-insertion/http-header-insertion-understand-custom-headers.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/http-header-insertion/http-header-insertion-understand-custom-headers.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 14:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440293#M99883</guid>
      <dc:creator>DavidWalters2</dc:creator>
      <dc:date>2021-10-12T14:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Want to block personal gmail and allow corporated gmail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440373#M99886</link>
      <description>&lt;P&gt;Indeed, historically this is accomplished through HTTP header insertion described above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An alternative method would be the new &lt;A href="https://docs.paloaltonetworks.com/saas-security/saas-security-admin/saas-security-inline/get-started-with-saas-security-inline/whats-saas-security-inline.html" target="_self"&gt;SaaS Security Inline subscription&lt;/A&gt;, some of my customers opt for the latter as it's much easier to configure and manage.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 20:20:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440373#M99886</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-10-12T20:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Want to block personal gmail and allow corporated gmail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440454#M99901</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615"&gt;@LAYER_8&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133292"&gt;@DavidWalters2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guys thanks for the reply.&lt;/P&gt;&lt;P&gt;I not getting your solution please explain in details.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Do you have any idea about this?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 06:31:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440454#M99901</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-10-13T06:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Want to block personal gmail and allow corporated gmail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440583#M99918</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133292"&gt;@DavidWalters2&lt;/a&gt;&amp;nbsp;'s answer covers it in detail. If you click the link you will see next to the header value:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;A title="" href="https://support.google.com/a/answer/1668854?hl=en" target="_blank" rel="noopener"&gt;support.google.com/a/answer/1668854?hl=en&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;You can allow access to specific Google accounts from your domain. The values that you give to this header are your domain and subdomains.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;To successfully insert headers for Google applications, you must also:&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;Create an SSL&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-profile.html" target="_blank" rel="noopener"&gt;decryption profile&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that includes the following categories and URLs:&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;business-and-economy&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;computer-and-internet-info&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;content-delivery-networks&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;internet-communications-and-telephony&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;low-risk&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;online-storage-and-backup&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;search-engine&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;web-based-email&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;drive.google.com&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;*.google.com&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;*.googleusercontent.com&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;*.gstatic.com&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;HTTP header insertion is not currently supported for HTTP/2. To insert headers, downgrade HTTP/2 connections to HTTP/1.1 using the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Strip ALPN&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;feature in the appropriate decryption profile. For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/pan-os/9-1/pan-os-admin/app-id/http2#idd9f6bba9-2d76-4a1a-b64c-bcea93d2962e" target="_self"&gt;App-ID and HTTP/2 Inspection&lt;/A&gt;.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;A title="" href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/define-traffic-to-decrypt.html" target="_blank" rel="noopener"&gt;Create rules&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to block the Quick UDP Internet Connections (QUIC) App-ID and place them at the top of your security policy because the firewall does not support header insertion for this protocol. When you do, the app reverts to using HTTP/2 over TLS, which the firewall handles in the previous step.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;So you'll need an SSL decryption profile (guide &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEZCA0" target="_self"&gt;here&lt;/A&gt;), you will enable the "Strip ALPN" feature in the profile you create. You will then create a decryption policy on the above categories, also a block QUIC policy. Lastly, you will follow &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/http-header-insertion/http-header-insertion-create-predefined" target="_self"&gt;these steps&lt;/A&gt; to add the google header value to the sessions.&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 13 Oct 2021 16:37:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440583#M99918</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-10-13T16:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Want to block personal gmail and allow corporated gmail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440597#M99920</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615"&gt;@LAYER_8&lt;/a&gt;&amp;nbsp;Thankyou for reply&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I have to create a different URL filtering for that ?&lt;/P&gt;&lt;P&gt;I attached the images plz help me out my config is right or wrong.&lt;/P&gt;&lt;P&gt;What should i add into the value and domains?&lt;/P&gt;&lt;P&gt;Is the security policy is correct ?&lt;/P&gt;&lt;P&gt;And what should I enable in the decryption profile?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture 1.PNG" style="width: 529px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36988i705A6AA643BF004B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture 1.PNG" alt="Capture 1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture 2.PNG" style="width: 831px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36989iD1F105EDA812A87A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture 2.PNG" alt="Capture 2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture 3.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36990iE05EA686A79CFB8A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture 3.PNG" alt="Capture 3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 17:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-block-personal-gmail-and-allow-corporated-gmail/m-p/440597#M99920</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-10-13T17:12:52Z</dc:date>
    </item>
  </channel>
</rss>

