Tuesday, December 18, 2018

Palo Alto FW - blocking USTREAM and BBC player

Greetings fellow users.

I'm playing around with Palo VM and having an issue blocking certain apps like BBC player and USTREAM.

Policy is dead simple - rule to deny FB\BBC\USTREAM followed by generall Allow ALL rule.
There's no SSL decryption at this stage.
Now FB block works fine, but BBC player and USTREAM are not blocked. I can see how BBC player can slip without SSL decrypion, but USTREAM is plaintext.

IS that an issue with Application Signature accuracy or i'm missing something here?
And yes, I'd rather do it via Application FW then URL filtering if possible.

Cheers.



No comments:

Post a Comment