- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-04-2023 10:02 AM
Hello Everyone,
Does anyone have a way to block Yahoo web-based email without enabling decryption?
1. I have read through the forums, and tried blocking with a URL Profile with the following url configs.
*.mail.yahoo.com
*.mail.yahoo.com/
mail.yahoo.com
mail.yahoo.com/
*.mail.yahoo.com/*
mail.yahoo.com/*
2. I have also tried just blocking standard webbased email in the default URL category. I also tried denying yahoo mail base via a securtiy policy.
None of the above works unless Decryption is enabled on the Palo. Basically they can go to Yahoo.com and click on the mail icon and get there. Unfortunately I can't block the login screen becuase they need for other parts of Yahoo (ie Yahoo finance). Any recommendations would be appreciated. Unfortunately the customer doesn't want to enable Decryption.
Thanks in advance for all of you advice.
10-04-2023 10:15 AM
If you can grab a test client and associated a url-filtering profile that has everything set to alert, you should be able to see exactly what the firewall is seeing as far as what URL clients are visiting. You should be able to use those logs to build out a block at that point, or confirm that you won't be able to block it without affecting access to the other Yahoo services that they need.
Taking a brief glance at unencrypted traffic matching mail.yahoo.com, looks like you should be able to block this with what you have. Ensure that your deny rule also accounts for the traffic being identified as yahoo-mail and not just ssl/web-browsing.
10-04-2023 11:26 AM
I did find all of the websites it was reaching out to (screen shot is below). I did put all of those websites in the URL filtering profile as a block (added them with wildcards and Carets as well). When I log in to Yahoo, I can still get to the Mailbox (screen shot of that below as well). The only way I that is blocked is if I enable Decryption on the firewall. I have denied traffic to all yahoo mail bases on any service through a policy and the mail link in the screen shot below still goes to my mailbox.
10-05-2023 02:55 PM
Hello,
On your URL filter, you can just block web-based-email category. If you need to allow any, just put the allowed websites above that policy.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!