URL FILTERING

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

URL FILTERING

L1 Bithead

 

 

dear engineers.
could you help me!!

I have the following problem with the URL filter:

I commented that I have blocked the streaming media category in which enters youtube

when I open firefox without any problem with the rule applies both http and https.
But when I open the page with chrome does not apply the rule.

I can do help me !!!

 



chromeyou.JPG
firefoxyou.JPG

4 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Chrome might use quic as application.

Try what happens if you block that in your sec policy.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

besides blocking Quic, you will also need to make sure SSL decryption is enabled

 

youtube uses SSL by default on a certificate from it's parent company google, so without SSL decryption, the only information available is the common name in the certificate, which is *.google.com

 

2016-05-02_09-09-15.jpg

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

Actually it should be possible for the firewall (depending on the PAN-OS Version) to see www.youtube.com (even without decrypting the connection) in the SNI extension of the ssl-handshake

 

Snap 2016.05.02 - 002.jpg

View solution in original post

you're right! i forgot about SNI there for a second 🙂

 

ok, must be 'quic' thats enabled by default in chrome 😉

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

5 REPLIES 5

Cyber Elite
Cyber Elite

Chrome might use quic as application.

Try what happens if you block that in your sec policy.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

besides blocking Quic, you will also need to make sure SSL decryption is enabled

 

youtube uses SSL by default on a certificate from it's parent company google, so without SSL decryption, the only information available is the common name in the certificate, which is *.google.com

 

2016-05-02_09-09-15.jpg

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Actually it should be possible for the firewall (depending on the PAN-OS Version) to see www.youtube.com (even without decrypting the connection) in the SNI extension of the ssl-handshake

 

Snap 2016.05.02 - 002.jpg

you're right! i forgot about SNI there for a second 🙂

 

ok, must be 'quic' thats enabled by default in chrome 😉

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Apply the protocol blocking google youtube quic and everything was blocked.
I also discovered that you can disable the protocol from chrome.
chromequic.JPG
thank you very much.
  • 4 accepted solutions
  • 3900 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!