- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-03-2025 06:06 PM
Hi All,
I want to share my experience on very latest configuration I did in my company Firewall infra. With the genAI evolution & most of the companies trying to develop their own homegrown genAI app, it was becoming headache for my Cyber Risk team to track usage of 3rd party genAI apps (like ChatGPT, Gemini) & doing comparative analysis of traffic for external genAI vs internal genAI usage. Risk also wanted to deter colleagues from uploading company's data on unapproved sites, get logging visibility for personal files sharing, third party email & at same time wanted effective user education in place with list of guidelines to use such apps with caution was very critical for them to issue warning/splash screen.
I discussed these challenges with Risk team and inspired with some hands-on SANS training and getting some skin in the game with my domain expertise came up with idea and implemented a solution using via PANW firewalls "Response page" feature.
Solution :
(i) Between the Browser/client and the Firewall- serve up the continue page over http:6080 ( log action : block-continue explained later)
(ii) Between the Firewall and the Destination website- serve as the direct interaction between user and website after “continue” (although firewall on behalf of client/user machine is talking to server(website). In such interaction firewall can log additional fields like uploaded file names, user IP, user-id, timestamp, app-id etc. Later you can see related logs in “Data-filtering” logging section for such traffic.
Considerations :
After implementing & testing this solution you will notice that URL address bar has unfriendly address over port 6080. This pertains to flow Step 6 (i) explained above and is seen because :The "Continue Page" requires a user interaction (clicking the continue button) which needs to be served up by a web service. The ports 6080-6082/TCP are web service that the firewall is using as a landing spot for that page. The URL in the client browser unfortunately cannot be changed as it contains all the needed information for the firewall to track the redirection session to a specific user. This is a required step to achieve this functionality and cannot be altered. When the user clicks the "Continue" button the acknowledgment is sent to the webservice and the originally blocked firewall session is now allowed.
Please feel free to share comment, feedback.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!