- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
11-11-2019 04:33 PM
PANOS 8.1
Hi all - I have ongoing issues with trying to control downloading of files from CDNs. An easy example is .cab files used by Microsoft Office templates. When you download a template it goes off to a page off: templatesmetadata.office.net, but the actual file is stored in an Akamai cache.
I have a policy matching a custom URL category, allowing that (I've also tried *.office.net), URL. This policy has no file blocking profile.
This does not seem to work. However, if I exclude *.office.net from decryption it works around the issue and allows the download.
I don't understand why it would match for the no-decrypt policy, but not the URL category policy.
What is the correct and manageable way to allow downloads from CDNs where the container URL is known and trusted?
Thanks,
Shannon
11-12-2019 01:05 AM
Good Day
I am just thinking out loud here, yet if you created a policy that allowed outbound traffic and used the URL filtering as a security profile (instead of using your custom url category as a matching condition) you may have some better luck (I believe)
I typically use an application such as web-browsing and ssl in combination of a URL matching condition in my policies.
Maybe, if you find out what the application that is being used, when accessing the Akami, you could give this a shot.
But I still believe the category should be used in your URL filtering profile, even if you need to create a custom rule/category/profile for your downloads.
Hope this makes sense to you. 😛
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!