web file blocking

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

web file blocking

L0 Member

Hello Community,

We are trying to implement file upload/download blocking for W-Web in our environment using a Palo Alto firewall.

Current setup:

SSL Forward Proxy decryption is enabled.

A decryption certificate has been created on the firewall and installed in the Trusted Root Certification Authorities store on client machines.

Security policy and File Blocking profile are configured to block file transfers for watsapp Web.

Issue observed:
Even after installing the firewall decryption certificate on the client machines, Wtsup Web continues to present the official Wtsapp certificate chain when verified from the browser. The firewall certificate is not being applied.


Questions:

Does Watsup Web use certificate pinning, which prevents SSL Forward Proxy decryption?

Is SSL Inbound Inspection or any additional SSL/TLS profile required for Wtsup Web file blocking?

Is it possible to block file transfers for Wtsup Web without SSL decryption, using App-ID or Content-ID?

Are there any known Palo Alto limitations or recommended best practices for Wtsup Web file blocking?

Any guidance or real-world experience on this would be greatly appreciated.

Thank you in advance for your support.



1 REPLY 1

L0 Member

 I have not used a decryption profile or anything similar. I just created a policy that allows Wtsapp-base, Wtsapp-chat, and Wtsapp-voice. Initially, I can see that Wtsapp upload and download are blocked, but if I click ‘try again’, I can upload the file. At first it is denied, but if I try again, the file transfer succeeds. Could someone please provide a solution if you are using this in your organization or have tried it in your lab and succeeded? 

  • 82 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!