11-29-2010 11:59 PM
Hi,
we have banned the http-proxy in school to stop them downloading and accessing sites they shouldn't, however they have now found using https based proxies bypasses this.
What is my next possible solution in my ever on going war with students.
Any advice / help much appreciated.
Thanks in advance.
Darren
12-07-2010 01:19 PM
OK.
Looking at the URL categorisation for this site in brightcloud it comes up in the "proxy Avoid and Anonymizers" category - so the simplest solution would be to apply a URL filter profile which blockas this category in its entirety (deny) and apply that profil to your outbound interface.
Because it's an atempted SSL connection, the users will get no nice "Access denied" banner because the PA can't do that for HTTPS connections - but it should block them anyway owing to the database categorisation.
Of course, if you don't have a valid web filter license you mgiht be in trouble. 🙂 I'm not sure if you can still create custom URL filter cetagories without the "general" web filter license, but you could try that also - create a custom URL filter category, add your proxy site to it, set it in a URL filter profile for "deny" with everything else allowed.
Or you could, as suggested, so SSL decrypt and stop them that way.
Cheers.
12-08-2010 12:11 AM
Dagibbs,
I cannot award myself the Answer points, so I will give them to you for your help.
Darren
12-08-2010 12:50 AM
Liking your style
01-06-2011 05:49 AM
Can you share how you set up the SSL Decryption with another school district tech having the same issue? I'm not having any luck. Thanks!
01-08-2011 01:34 PM
There is a bug with application filtering, it doesn't seem to work on OS 3.1.5 or 3.1.6, not sure about previous version. I logged a ticket with PaloAlto but looks like the bug is not important so it won't be fixed until release 4.
01-08-2011 06:43 PM
Hi tontabill,
I am sure if you work with your local sales team on the issue prioritisation they will help you.
Best Regards
James
01-13-2011 01:20 AM
KRboerts,
there is a PM waiting for you.
Darren
03-07-2013 06:32 AM
I just got into the PA this past year. Would you mind sharing how you set up the SSL Decryption with our school?
03-07-2013 03:59 PM
Try going here: https://live.paloaltonetworks.com/docs/DOC-2008
07-31-2020 01:57 AM
For the safety of data transportation, experts advise students to use the HTTPS protocol, because any information entered using SSL is encrypted, so in case of interception, the attacker receives a random set of characters and can download your dissertation.
https://customwritingz.net
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!