- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-08-2014 04:38 AM
Hello Gents,
We are facing an Issue with Palo Alto 5050, since we found some web proxies not seen by the Appliance, like
and most of the dynamic proxies in this website are working
Regards,
Maher
03-09-2014 10:12 AM
Alternatively
if you use decryption you can easly use custom url objects and Url filtering profile without URL license.
you don't need a license for that.Just select this url profile for the realted traffic's policy.
03-08-2014 12:54 PM
They seem to be blocking on my Palo Alto Networks firewall. Do you have the "proxy-avoidance-and-anonymizers" category set for block?
03-08-2014 08:34 PM
Hi Jared,
I don't have URL license, I'm using only application filters. So I blocked all proxy and encrypted tunnels applications. and it doesn't work.
Regards,
Maher
03-08-2014 09:30 PM
Do you have an SSL Decryption policy configured and in use? Without decryption the application will be viewed as ssl, which I assume is permitted in your security policy.
03-09-2014 04:08 AM
Yes, I've decryption policy in use that decrypts all the traffic.
Appreciated.
Maher
03-09-2014 07:16 AM
You can use fqdn objects (in destination ip) for these two url and deny any traffic.So sites will not work even you use or do not use decryption.
03-09-2014 08:39 AM
Hi panos,
thanks for your support, but it's not allowed to use FQDN in the destination IP.
Regards,
Maher
03-09-2014 08:44 AM
You should first create these as fqdn object like below
Then you can use these objects inside policy
03-09-2014 10:12 AM
Alternatively
if you use decryption you can easly use custom url objects and Url filtering profile without URL license.
you don't need a license for that.Just select this url profile for the realted traffic's policy.
03-15-2014 01:18 AM
Thanks panos,
all is going very well now.
Appreciated.
Maher
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!