Website blocked based on key words

Reply
L3 Networker

Website blocked based on key words

Hi,

I am having issues accessing this website: http://social.technet.microsoft.com/Forums/systemcenter/en-US/04400522-edd7-412f-8461-276ca3c0c88c/s...

The firewall blocks it based on the File Blocking profile that includes bat and cmd files among the file types that should be blocked; however, the site does not contain a bat file, but rather the word batch and commands from a batch file pasted in the forum. I find this rather strange, as the File Blocking filter should only look at the files extensions.

Tags (3)
L7 Applicator

Re: Website blocked based on key words

Hello Sir,

I do agree with you. The PAN FW is blocking this URL with below mentioned information under "data-filtering" log.

File-blocking-1.JPG.jpg

The specified URL contains  some of the windows batch files output on this discussion. I hope that triggers the signature to block the content, because the PAN firewall is signature based not based on file-extension/URL. 

For example: If you transfer a txt file which contains signature of a EXE file, the PAN will identify that file as EXE not TXT.

Thanks

L3 Networker

Re: Website blocked based on key words

Thank you; I guess not much we can do to allow these type of websites, but still blocking actual bat files.

L3 Networker

Re: Website blocked based on key words

Is there any way we can create an exception, so outputs of bat files are not blocked on certain URLs, like this particular one?

L7 Applicator

Re: Website blocked based on key words

Hello Sir,

You can create a custom URL category and attach along with a profile.

Example: 

http://social.technet.microsoft.com

*.social.technet.microsoft.com/*

Thanks

L4 Transporter

Re: Website blocked based on key words

Hi MMCiobanu

To add to Hulks point after creating custom url category for the specified site or sites having similar issue and configure the URL profile with this custom url profile. Also make sure no Data filtering is enabled for this security rule so that it does not process the Bat files.

L3 Networker

Re: Website blocked based on key words

Yes, the website is allowed as part of the URL custom category; but, it seems to be blocked by the Data Filtering profile, which includes blocking bat, cmd, exe files.

I will try your suggestion and disable Data Filtering on that specific rule.

Thank you.

L3 Networker

Re: Website blocked based on key words

The problem I see with this is that, because the Data Filtering is actually blocking the site, I can't have trust-any to untrust-any without data filtering, while I have one already with data filtering enabled. It does not look like I can have a rule only for a particular URL with Data Filtering off.

L6 Presenter

Re: Website blocked based on key words

You can do this by the steps :

1- configure the custom url object as

custom.png

2- Create an address object

obj.png

3- Use a policy with destination address object and URL Category object with web-browsing application without any Data filtering profile.

policy.png

Page will be loaded correctly.

Highlighted
L3 Networker

Re: Website blocked based on key words

Thank you; This worked well.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!