Vigyata.AI
Is this your channel?

#paloaltofirewalltraining | Day 34 | How to block Facebook | Detailed Explanation | Lab

1.6K views· 29 likes· 16:11· Apr 6, 2025

🛍️ Products Mentioned (2)

Join this channel to get access to perks: https://www.youtube.com/channel/UCBujQdd5rBRg7n70vy7YmAQ/join Please checkout my new video on How to block Facebook. If you like this video give it a thumps up and subscribe my channel for more video. Have any question put it on comment section Recommend Video https://youtu.be/i_3UCXy_T0g Recommend Link (Playlist for EVE-NG LAB Setup) https://www.youtube.com/playlist?list=PLaUiizP3D7fPMmUQqS5QKX_FVSoMP68Z5 Palo Alto Certification information URL: https://www.paloaltonetworks.com/services/education For Palo Alto Documentation https://docs.paloaltonetworks.com/ Please follow me Instagram : https://www.instagram.com/bikashtech Twitter : https://twitter.com/Bikashshaw82 E-mail ID : bikashshaw261@gmail.com #Paloaltotraining ##bikashtech #paloaltofirewalltraining #paloaltonetworks #url #sslcertificate #ssl

About This Video

Hello friends, welcome to Day 34 of my PCNSA series. In this lab I explain a very common real-world requirement: how to allow Facebook but block specific features inside it—like videos, chat, rooms, games, etc. In my previous video I covered blocking a specific URL and how External Dynamic List works, but today the focus is application control with sub-features and why SSL decryption is the key part. I start by creating a security policy to allow only the “facebook-base” application (plus DNS, because facebook.com must resolve). Without decryption, you’ll notice Facebook loads and even videos can still play, which confuses many people in production. Then I implement an SSL Forward Proxy decryption policy and retest—now only the base Facebook page works, and inner features like videos stop working because the firewall can finally see the sub-application properly. After that, I show how to selectively allow a sub-feature (example: facebook-video) and commit again, and you can see the video starts working. Finally, I verify everything from the Monitor logs to confirm what is allowed and what is getting blocked. The takeaway is simple: if you want to control sub-applications inside HTTPS apps, SSL decryption is mandatory.

Frequently Asked Questions

🎬 More from Bikash's Tech