HTTP Post methods

L0 Member

HTTP Post methods

HI

Is there an way that i can create an custom application on PAN to block all HTTP post methods for a specific website or a group of websites? I did try by using some things as follows but dint realy work

Post method.jpg

SRA
L4 Transporter

Re: HTTP Post methods

L0 Member

Re: HTTP Post methods

Hi Savasarala,

Thank you for the inputs, i had taken facebook as an example. Is there a way to turn off the HTTP POST method irrespective of any specific website? i.e POST Method on any website is blocked.

Regards,

Sumukh Rao

L5 Sessionator

Re: HTTP Post methods

This should be possible using a custom application signature. There is an example of how to create such a custom app in the PAN-OS 4.0 Administrator's Guide.

https://support.paloaltonetworks.com/index.php?option=com_pan&task=dl_tech_doc&filename=PA-4.0_Admin...

Page 163 gives an example of how to detect a POST to a blog site, though really it could be any website.

-Richard

L2 Linker

Re: HTTP Post methods

Good discussion, We are looking for similar filtering for any HTTP or HTTPS post, instead of blocking we would like to capture whats been posted and log it. So, that it could be used for investigation purpose. Is this something possible using PAN products?

Not applicable

Re: HTTP Post methods

Hi Guys   I have been trying to get something similar to allow "http read" but drop "http write"(put, post, delete)  and i am not able to create the application in version 5.0 as it does not corresponds with the Docs. Was wondering if someone knew how to do this.

JM

L0 Member

Re: HTTP Post methods

Hi,

You can block all http post requests using a vulnerability profile.

Please have a look at the following KB:

Rgds

Raf

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!