File Blocking rule logic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

File Blocking rule logic

L2 Linker

The following KB article states that the File Blocking rulebase is not top-down but based on action precedence. The article fails to mention anything on the function of the application column with regard to processing logic:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGeCAK

 

If for instance, I have a security rule that allows any application, and in the attached File Blocking profile I have a "Block Webmail EXE" rule that blocks on .exe file types, and has Gmail configured in the application column.

 

Next I have a "EXE Alert" file blocking rule that alerts on .exe file types and has "Any" application specified.

 

According to the above article, if a file type matches multiple File Blocking rules, the rule with the highest precedence action will win (block in this case). But what about the application column? If the application being used is web browsing and the "Block Webmail EXE" rule is only configured for Gmail, would it still block the file? Or would it recognize that this session is Web-Browsing, not Gmail, and match instead on the other "EXE Alert" rule?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@nsendelbac ,

The application is taken into account when analysing the traffic. So if you block EXEs specifically for Gmail and set all others to alert, it will only block EXEs from any traffic identified as Gmail traffic. 

The only thing to keep in account here is that the traffic needs to be identified correctly for that policy to function correctly. If you aren't decrypting traffic your Gmail traffic might not always be getting identified correctly. 

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

@nsendelbac ,

The application is taken into account when analysing the traffic. So if you block EXEs specifically for Gmail and set all others to alert, it will only block EXEs from any traffic identified as Gmail traffic. 

The only thing to keep in account here is that the traffic needs to be identified correctly for that policy to function correctly. If you aren't decrypting traffic your Gmail traffic might not always be getting identified correctly. 

  • 1 accepted solution
  • 3440 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!