- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-21-2019 08:25 AM
The following KB article states that the File Blocking rulebase is not top-down but based on action precedence. The article fails to mention anything on the function of the application column with regard to processing logic:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGeCAK
If for instance, I have a security rule that allows any application, and in the attached File Blocking profile I have a "Block Webmail EXE" rule that blocks on .exe file types, and has Gmail configured in the application column.
Next I have a "EXE Alert" file blocking rule that alerts on .exe file types and has "Any" application specified.
According to the above article, if a file type matches multiple File Blocking rules, the rule with the highest precedence action will win (block in this case). But what about the application column? If the application being used is web browsing and the "Block Webmail EXE" rule is only configured for Gmail, would it still block the file? Or would it recognize that this session is Web-Browsing, not Gmail, and match instead on the other "EXE Alert" rule?
06-22-2019 05:09 AM
The application is taken into account when analysing the traffic. So if you block EXEs specifically for Gmail and set all others to alert, it will only block EXEs from any traffic identified as Gmail traffic.
The only thing to keep in account here is that the traffic needs to be identified correctly for that policy to function correctly. If you aren't decrypting traffic your Gmail traffic might not always be getting identified correctly.
06-22-2019 05:09 AM
The application is taken into account when analysing the traffic. So if you block EXEs specifically for Gmail and set all others to alert, it will only block EXEs from any traffic identified as Gmail traffic.
The only thing to keep in account here is that the traffic needs to be identified correctly for that policy to function correctly. If you aren't decrypting traffic your Gmail traffic might not always be getting identified correctly.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!