I am having issues accessing this website: http://social.technet.microsoft.com/Forums/systemcenter/en-US/04400522-edd7-412f-8461-276ca3c0c88c/s...
The firewall blocks it based on the File Blocking profile that includes bat and cmd files among the file types that should be blocked; however, the site does not contain a bat file, but rather the word batch and commands from a batch file pasted in the forum. I find this rather strange, as the File Blocking filter should only look at the files extensions.
I do agree with you. The PAN FW is blocking this URL with below mentioned information under "data-filtering" log.
The specified URL contains some of the windows batch files output on this discussion. I hope that triggers the signature to block the content, because the PAN firewall is signature based not based on file-extension/URL.
For example: If you transfer a txt file which contains signature of a EXE file, the PAN will identify that file as EXE not TXT.
To add to Hulks point after creating custom url category for the specified site or sites having similar issue and configure the URL profile with this custom url profile. Also make sure no Data filtering is enabled for this security rule so that it does not process the Bat files.
The problem I see with this is that, because the Data Filtering is actually blocking the site, I can't have trust-any to untrust-any without data filtering, while I have one already with data filtering enabled. It does not look like I can have a rule only for a particular URL with Data Filtering off.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!