- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-05-2011 03:04 AM
I have recently deployed PAN 2050 in my organization. We are enabled file blocking for selected file types e.g. (EXE, BAT, CAB, ZIP, ISO, RAR etc.) in both the direction. But as per management decision I have to allow download access from Microsoft URL’s. As you are aware Microsoft is having hundreds of IP’s so I can’t achieve this using IP address. Is there any way to allow download access using the URL or domain name?
04-05-2011 10:44 AM
Hi There,
Yes, you should be able to do this with a custom App-ID. Within the App-ID, use web-browsing as the parent application and create a regular expression looking for microsoft.com in the URI header. You may have to play around with this to get it right and make sure you don't affect other App-ID's for Microsoft applications/updates. Use that custom application in a Security Policy rule and attach a file-blocking profile that allows those file types. Make sure this Security rule is above your other rule with the more restrictive file-blocking profile.
Cheers,
Kelly
04-05-2011 10:44 AM
Hi There,
Yes, you should be able to do this with a custom App-ID. Within the App-ID, use web-browsing as the parent application and create a regular expression looking for microsoft.com in the URI header. You may have to play around with this to get it right and make sure you don't affect other App-ID's for Microsoft applications/updates. Use that custom application in a Security Policy rule and attach a file-blocking profile that allows those file types. Make sure this Security rule is above your other rule with the more restrictive file-blocking profile.
Cheers,
Kelly
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!