- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-17-2015 05:59 AM
Hello To All,
We've a PA-500 which is linked to the AD. The idea is to block Facebook for a group of users.
The thing is when those users will be logged (login and password), the AD update the PA-500.
To block facebook for those users, What should be done?
-1- Create a group of users
-2- Create a Policy which include those users and a Deny rule for facebook
DO we need something else?
Thanks for your support and comments.
Rgds
M
04-17-2015 08:04 AM
rule 1: allow Facebook AD group to access Facebook application(s), in the image below basically add your AD group in the users and assign a url profile allowing the social media url group (or custom group to just allow facebook url)
rule 2: block all users from Facebook applications, basically match above rule as a block.
rule 3: in your general surfing rule allow social media (or you custom group in rule 1) to avoid block messages if you are not doing ssl decryption
04-17-2015 07:17 AM
yes that is basically it, keep in mind if you are not doing ssl decryption on the social media url category blocked users will not get a blocked message. a solution if you are not ready for ssl decryption is to allow all users to get to the url category of social media but block by application. this will allow them to get to the login page but when they try to login they will get a block because of the application if they are not in your allowed group by application.
04-17-2015 07:23 AM
Thanks for your feedback,
How do you proceed on the policy.. Could you please give me an example on how to configure the policy rule?
04-17-2015 08:04 AM
rule 1: allow Facebook AD group to access Facebook application(s), in the image below basically add your AD group in the users and assign a url profile allowing the social media url group (or custom group to just allow facebook url)
rule 2: block all users from Facebook applications, basically match above rule as a block.
rule 3: in your general surfing rule allow social media (or you custom group in rule 1) to avoid block messages if you are not doing ssl decryption
04-17-2015 08:16 AM
Thanks a lot for your quick support !!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!