04-21-2021 06:29 AM
I have created a rule which allow the wetransfer (download and upload) application.
But when a user receive an email to download a file the url is we.tl/random numbers.
When the user clicks it the firewall doesn't see it as the application wetransfer-download but as category online storage and backup.
Is this a bug in the Pan-OS and how can we solve this?
05-06-2021 01:38 AM
Yeah we found a solution.
We created an application group with the file sharing apps we allow. This is wetransfer and google drive.
After that I created a policy rule called File sharing app, allowed the users who may use these apps, set the Application to the application group we created and in the URL filtering we allowed the category online storage and backup. We created a seperate URL filtering for this policy rule.
04-21-2021 07:44 AM
I don't use Wetransfer so I can't speak to the accuracy of the App-ID, but just to confirm, are you decrypting the traffic? If you are and it's still not registering properly, you can submit it to TAC to request the existing ID be modified to capture the traffic properly.
04-22-2021 02:52 AM - edited 04-22-2021 05:09 AM
Yeah we are decrypting the traffic. But doesn't get recognized as the correct app-id.
The link that get's opened is download.wetransfer.com/
The problem is that the app-id is wetransfer downloading which is allowed, but the url download.wetransfer.com is in the URL categorie online backup and storage and that is a block categorie in our environment. So one rule is over rulling the other one.
04-22-2021 07:19 AM
@ZEBIT so the app-id is getting recorded correctly, or it isn't? You are likely just running into an order of operations issue honestly. IE: If you are blocking the URL category the firewall may not be able to classify the traffic properly before the traffic is identified as online backup and storage and dropped by whatever rule you have denying that traffic.
04-23-2021 12:11 AM
@BPry I have rules which allows app like wetransfer download and no URL filtering. After this rule I have a rule with URL filtering.
When we we hit the site download.wetransfer.com the app rule doesn't get hit but the URL filtering rule.
After allowing the category online storage and backup the site get recognized as wetransfer-download.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!