Skip to content

appid

Can we really block Tor?

Some time ago, I wrote an article about how simple techniques can bypass firewall protections: How to Trick a Firewall and Bypass Protections. One of the methods discussed in that post was using Tor (The Onion Router). Beyond bypassing firewalls, Tor can be leveraged by threat actors to establish persistence in targeted environments. Google Cloud… Read More »Can we really block Tor?

Palo Alto Networks App-ID tips

App-ID, core Palo Alto Networks firewalls capability was elaborated at high level perspective on below blog post: Like mentioned above, all traffic flowing through the firewall is inspected by App-ID engine. Is NGFW able to identify every packets at layer 7? Of course not, what happening than and how knowledge about App-ID operations can be… Read More »Palo Alto Networks App-ID tips

Palo Alto Networks App-ID

What is application ID or application control? Firewalls vendors have different naming conventions. Normally, as match criteria in firewall access policies layers 3 and 4 can be used. So, access policies can be configured based on ip addresses and ports. Are there any issue with L3/L4 access policies? First example, let’s allow/block access to Facebook/Gmail/Netflix… Read More »Palo Alto Networks App-ID