prevent file copy over ssl vpn

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

prevent file copy over ssl vpn

L0 Member

Hi all

 

is there a way to prevent file copy over ssl vpn tunnel. user work from connects via SSL VPN and we want to make they cannot copy file to their personal PC. we have disabled RDP clipboard but thats not enough.

 

regards

4 REPLIES 4

L5 Sessionator

Hi @Wadhwani

 

This is possible. You'll want to look into SSL Decryption!

 

Be advised, the configuration part of decryption can be quite quick - most of the time spent is with preparation, planning and rollout.

 

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption

 

https://www.paloaltonetworks.com/features/decryption

 

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-and-Test-SSL-Decryption...

 

Thanks,

Luke.

 

Hi Luke

 

Thank you for quick reply, can i do SSL Decryption for any ssl vpn or it needs to have palo alto vpn. we are not useing palo alto for any vpn.

 

 

Hi @Wadhwani,

 

With SSL Decryption enabled, the firewall will decrypt any SSL traffic that passes through it minus the below. As long as your SSLVPN traffic isn't identified as an App-ID or domain from the below article you should be good to go.

 

https://live.paloaltonetworks.com/t5/Configuration-Articles/List-of-Domains-and-Applications-Exclude...

 

Thanks,

Luke.

 

Cyber Elite
Cyber Elite

@Wadhwani

Just to verify; you are talking about a user connecting to an SSL VPN (such as GlobalProtect) and being able to identify the traffic that is activly traversing within that VPN? 

  • 3821 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!