Opening file download for specific URLs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Opening file download for specific URLs

Not applicable

I have recently deployed PAN 2050 in my organization. We are enabled file blocking for selected file types e.g. (EXE, BAT, CAB, ZIP, ISO, RAR etc.) in both the direction. But as per management decision I have to allow download access from Microsoft URL’s. As you are aware Microsoft is having hundreds of IP’s so I can’t achieve this using IP address. Is there any way to allow download access using the URL or domain name?

1 accepted solution

Accepted Solutions

L4 Transporter

Hi There,

Yes, you should be able to do this with a custom App-ID.  Within the App-ID, use web-browsing as the parent application and create a regular expression looking for microsoft.com in the URI header.  You may have to play around with this to get it right and make sure you don't affect other App-ID's for Microsoft applications/updates.  Use that custom application in a Security Policy rule and attach a file-blocking profile that allows those file types.  Make sure this Security rule is above your other rule with the more restrictive file-blocking profile.

Cheers,

Kelly

View solution in original post

1 REPLY 1

L4 Transporter

Hi There,

Yes, you should be able to do this with a custom App-ID.  Within the App-ID, use web-browsing as the parent application and create a regular expression looking for microsoft.com in the URI header.  You may have to play around with this to get it right and make sure you don't affect other App-ID's for Microsoft applications/updates.  Use that custom application in a Security Policy rule and attach a file-blocking profile that allows those file types.  Make sure this Security rule is above your other rule with the more restrictive file-blocking profile.

Cheers,

Kelly

  • 1 accepted solution
  • 2079 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!