How to block bloody youtube?

Reply
Highlighted
L2 Linker

How to block bloody youtube?

Ok, the task is stimple. I want to allow only one particular URL accessible from youtube. Let's say the URL is this:

https://www.youtube.com/watch?v=-RyESqegW9Y&

I created a custom URL category and put this URL into it: *.youtube.com/watch?v=-RyESqegW9Y

 

SSL decryption is enabled and working in my network.

 

I created another Custom URL category that has this list of URLs. This category will be sitting in the blocking rule.

youtube.com/watch
youtube.com/embed
www.youtube.com/watch
www.youtube.com/embed
*.youtube.com/watch
*.youtube.com/embed

 

I created 3 rules:

1: Allow youtube application to the permitted URL catergory (the first one).

2. Block everything that falls into the second Custom URL

3. Allow everything else. That "everything else" rule has URL-filtering enabled where the second custom-URL is set to "block".

 

Logically everything looks correct.

Now when I go to youtube first time from a newly opened firefox browser, everything is appearing fine. You can open youtube site, but can't open any video except the permitted one. The certificate is appearing issued by me, all good.

 

But then here is a workaround that just driving me nuts and I don't get how this happens:

If you go to any channel that has a built-in auto-play video in its splash page (like this: https://www.youtube.com/channel/UCLBzF3SZoIccFEpNaYa1E6Q) - you will see the video is being played. If I open this video full-screen, watch for few seconds and then return back to normal mode, i can watch any video on youtube after that. I noticed that sometimes the certificate is no longer being replaced by own, but sometimes it's still my cert being used.

 

There is nothing meaningful in the logs. Url-filtering just doesn't show anything like I've never gone to the blocked resource, the traffic log sometimes show few incomplete and non-decrypted packets that falls into the blocking rule, and then there is traffic successfully going from google-video servers that falls into streaming-media category and youtube-streaming app.

 

Sometimes it just starts working by itself. But then you just go to those bloody hamsters channel, and after watching a video on this channel no blocks seem to be enabled again. Just watch any video on this channel and have full access to all youtube videos after that

 

So, what the hell is going on? How to block youtube ?

 

Thanks!

 

Highlighted
Community Team Member

Re: How to block bloody youtube?

YouTube is one of those beasts that when you cut off 1 head, 2 others appear in its place. 

Just when you think you have the magic combination of blocking, things change. 

 

Because of this, the support at PAN have worked to try to come up with an answer, and the following article is the latest that we have to do what you are asking,, please check it out and let us know what you think.

 

https://live.paloaltonetworks.com/t5/configuration-articles/how-to-allow-a-single-youtube-video-and-...

Stay Secure,
Joe
End of line
Highlighted
L2 Linker

Re: How to block bloody youtube?

Thank you Jdelio, this is exactly how I configured it, and it works till you go to that hamster show channel after which none of blocks are working and you can surf freely over youtube I have no idea why. quic and udp443 are blocked, so it's definitely not going over these protocols.

 

Is there any way to grab unencrypted packet capture between firefox and the internet? I tried to do packet capture on Palo, but it's all in TLS, so pretty much useless.

Highlighted
L2 Linker

Re: How to block bloody youtube?

Hello,

You can try this, in custom category filter *.googlevideo.com should be added. You can capture youtube main URL's with using chrome developer option just pressing F12 on keyboard and seleck network tab and reload page.

 

For testing I put *.youtube.com and *.googlevideo.com on custom category and it worked for me.

UP
Highlighted
L3 Networker

Re: How to block bloody youtube?

Hi ,

 

You have use this pattern in block category to block all the youtube videos

*.youtube.com/watch?   and add Url which should be allowed in allowed category https://www.youtube.com/watch?v=CG7WDmFpsjU

 

 

 

Thanks & Regards,
Sahithyan S
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!