[rank_math_breadcrumb]

only allow single YouTube video and rest of YouTube block in Paloalto

Posted by

How to Allow a Single/subset of YouTube Videos and Block All Other Videos

for that you require two step need to follow-

  1. SSL decryption needs to be enabled.
  2. QUIC protocol needs to be disabled because it bypasses SSL decryption
  1. Create a new Custom URL Category to allow only the wanted YouTube video(s).

Get to your URL filtering policy inside of the WebGUI > Objects > Custom Objects > URL Category.

Then click Add to create a new Custom URL Category.

A new window will pop up. Inside that new window, Give it a Name (youtube-allowed) and Description if you like, and then click Add again and put the following URLs listed along with any other videos that are needed.

GUI: Objects > Custom Objects > URL Category > Add

  1. Next, you will want to create a new second URL category in order to deny the rest of YouTube videos.
  • While still inside that URL Category window, click Add again, and then put in a name (Youtube-BaseURLs) and description if needed
  • Then insert the following URLs under Sites
  • Click OK.

3-Configure the firewall policy as shown below.

  1. Please verify that you have a decryption policy of type SSL Forward Proxy. The decryption policy should cover youtube traffic. One way is to define a decryption policy for the “streaming-media” URL category. Please see the following article about configuring SSL Decryption: How to Implement and Test SSL Decryption or see the SSL Decryption Resource List on Configuration and Troubleshooting.
  1. Commit and test.

When testing, you should be able to visit www.youtube.com and the links should appear to be active. But when you click on any video (other than the allowed video) you should get a block screen.

[the-post-grid id=”9538″ title=””]

Leave a Reply

Your email address will not be published. Required fields are marked *

Visit Our Store and Buy All document (F5, Zscaler, ASA, Paloalto, Checkpoint,Forescout, Cisco ISE etc) only in  1600RS, click here on store - Store

X
error: Content is protected !!