Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

App blocking

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

App blocking

L4 Transporter

Hi Friends,

is this possible to block facebook, gtalk, if i don't have URL filtering license, If yes then how please explain.

Regards

Satish

6 REPLIES 6

L7 Applicator

Hello Satish,

You can block traffic according to Application i.e facebook, gtalk .

Thanks

L7 Applicator

Palo ALto firewall is having multiple layer of security, if you do not have a valid URL filtering license, you may configure a security policy base on application to block facebook and gtalk traffic.

policy-1.JPG

Hope this helps.

Thanks

Hi Hulk Bro,

Thanks for your reply. i have already done this but still i m able to access the youtube, gtalk , facebook etc and my network diagram attached plz suggest . Smiley Happy Smiley Happy Untitledssssswdrqwdfadca.png

L4 Transporter

Hi Hulk

Are You sure that this is enought?

I mean is is possible to block such aplication without SSL decryptions on PA?

For example, if aps need ssl to be properly identyfied, and You allow ssl on this security rule or any other that is processed before IMHO this traffic will flow.

Please correct me if I'm wrong.

Regards

Slawek

Hello Slv,

For all predefined applications, you need not to have a decryption in place. The Palo Alto should automatically detect the signature and you have to allow it's dependent application.

Thanks

L5 Sessionator

Hi HULK and slv,

FYI:

I found following doc: Which App ID's Require Decryption?

This includes facebook and other features related to facebook (w/o facebook-base)

On the other hand, I tested with my PA-5020 which does not have decrypt rule, and confirmed that I can see 'facebook-base' without decryption.

Regards,

  • 2689 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!