- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
07-23-2014 06:36 AM
Hi Friends,
is this possible to block facebook, gtalk, if i don't have URL filtering license, If yes then how please explain.
Regards
Satish
07-23-2014 06:59 AM
Palo ALto firewall is having multiple layer of security, if you do not have a valid URL filtering license, you may configure a security policy base on application to block facebook and gtalk traffic.
Hope this helps.
Thanks
07-23-2014 09:15 AM
Hi Hulk Bro,
Thanks for your reply. i have already done this but still i m able to access the youtube, gtalk , facebook etc and my network diagram attached plz suggest .
07-23-2014 10:07 AM
Hi Hulk
Are You sure that this is enought?
I mean is is possible to block such aplication without SSL decryptions on PA?
For example, if aps need ssl to be properly identyfied, and You allow ssl on this security rule or any other that is processed before IMHO this traffic will flow.
Please correct me if I'm wrong.
Regards
Slawek
07-23-2014 11:02 AM
Hello Slv,
For all predefined applications, you need not to have a decryption in place. The Palo Alto should automatically detect the signature and you have to allow it's dependent application.
Thanks
07-24-2014 12:23 AM
Hi HULK and slv,
FYI:
I found following doc: Which App ID's Require Decryption?
This includes facebook and other features related to facebook (w/o facebook-base)
On the other hand, I tested with my PA-5020 which does not have decrypt rule, and confirmed that I can see 'facebook-base' without decryption.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!