Website blocked based on key words

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Website blocked based on key words

L3 Networker

Hi,

I am having issues accessing this website: http://social.technet.microsoft.com/Forums/systemcenter/en-US/04400522-edd7-412f-8461-276ca3c0c88c/s...

The firewall blocks it based on the File Blocking profile that includes bat and cmd files among the file types that should be blocked; however, the site does not contain a bat file, but rather the word batch and commands from a batch file pasted in the forum. I find this rather strange, as the File Blocking filter should only look at the files extensions.

1 accepted solution

Accepted Solutions

You can do this by the steps :

1- configure the custom url object as

custom.png

2- Create an address object

obj.png

3- Use a policy with destination address object and URL Category object with web-browsing application without any Data filtering profile.

policy.png

Page will be loaded correctly.

View solution in original post

9 REPLIES 9

L7 Applicator

Hello Sir,

I do agree with you. The PAN FW is blocking this URL with below mentioned information under "data-filtering" log.

File-blocking-1.JPG.jpg

The specified URL contains  some of the windows batch files output on this discussion. I hope that triggers the signature to block the content, because the PAN firewall is signature based not based on file-extension/URL. 

For example: If you transfer a txt file which contains signature of a EXE file, the PAN will identify that file as EXE not TXT.

Thanks

L3 Networker

Thank you; I guess not much we can do to allow these type of websites, but still blocking actual bat files.

Is there any way we can create an exception, so outputs of bat files are not blocked on certain URLs, like this particular one?

Hello Sir,

You can create a custom URL category and attach along with a profile.

Example: 

http://social.technet.microsoft.com

*.social.technet.microsoft.com/*

Thanks

Hi MMCiobanu

To add to Hulks point after creating custom url category for the specified site or sites having similar issue and configure the URL profile with this custom url profile. Also make sure no Data filtering is enabled for this security rule so that it does not process the Bat files.

Yes, the website is allowed as part of the URL custom category; but, it seems to be blocked by the Data Filtering profile, which includes blocking bat, cmd, exe files.

I will try your suggestion and disable Data Filtering on that specific rule.

Thank you.

The problem I see with this is that, because the Data Filtering is actually blocking the site, I can't have trust-any to untrust-any without data filtering, while I have one already with data filtering enabled. It does not look like I can have a rule only for a particular URL with Data Filtering off.

You can do this by the steps :

1- configure the custom url object as

custom.png

2- Create an address object

obj.png

3- Use a policy with destination address object and URL Category object with web-browsing application without any Data filtering profile.

policy.png

Page will be loaded correctly.

Thank you; This worked well.

  • 1 accepted solution
  • 6573 Views
  • 9 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!