block yahoo mail

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

block yahoo mail

L0 Member

Hello Everyone,

 

Does anyone have a way to block Yahoo web-based email without enabling decryption?

 

1. I have read through the forums, and tried blocking with a URL Profile with the following url configs.

*.mail.yahoo.com

*.mail.yahoo.com/

mail.yahoo.com

mail.yahoo.com/

*.mail.yahoo.com/*

mail.yahoo.com/*

 

2. I have also tried just blocking standard webbased email in the default URL category. I also tried denying yahoo mail base via a securtiy policy.

 

None of the above works unless Decryption is enabled on the Palo. Basically they can go to Yahoo.com and click on the mail icon and get there. Unfortunately I can't block the login screen becuase they need for other parts of Yahoo (ie Yahoo finance). Any recommendations would be appreciated. Unfortunately the customer doesn't want to enable Decryption. 

 

Thanks in advance for all of you advice.

3 REPLIES 3

Cyber Elite
Cyber Elite

@Andrew-Hiser,

If you can grab a test client and associated a url-filtering profile that has everything set to alert, you should be able to see exactly what the firewall is seeing as far as what URL clients are visiting. You should be able to use those logs to build out a block at that point, or confirm that you won't be able to block it without affecting access to the other Yahoo services that they need.

Taking a brief glance at unencrypted traffic matching mail.yahoo.com, looks like you should be able to block this with what you have. Ensure that your deny rule also accounts for the traffic being identified as yahoo-mail and not just ssl/web-browsing. 

I did find all of the websites it was reaching out to (screen shot is below). I did put all of those websites in the URL filtering profile as a block (added them with wildcards and Carets as well). When I log in to Yahoo, I can still get to the Mailbox (screen shot of that below as well). The only way I that is blocked is if I enable Decryption on the firewall. I have denied traffic to all yahoo mail bases on any service through a policy and the mail link in the screen shot below still goes to my mailbox.

mailbox.JPGwebsites..JPG

Cyber Elite
Cyber Elite

Hello,

On your URL filter, you can just block web-based-email category. If you need to allow any, just put the allowed websites above that policy.

Regards,

  • 3269 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!