Block application based on Hostname that has spaces
I'm looking for a way to block applications based on the "Hostname", but the "Hostname" has a space in it. For example, there is a Just Proxy VPN that is getting through our firewall. If I filter the Application Control log, the Application is SSL_TLSv1.2, and in the details, the Hostname is "Just Proxy VPN" and the URL is "/", and the Category is Network.Service. It uses different IP addresses and ports, so I can't block using those.
I can't block all of SSL_TLSv1.2, but I want to block any application using hostname= "Just Proxy VPN". I can filter for it in the logs, but I can't seem to setup a block for it. Is there a way to create an Application using this information to then block it?
Here is a detail log for one instance:
itime=2017-04-10 20:44:54 vd=root app=SSL_TLSv1.2 date=2017-04-10 dstip=139.59.64.226 apprisk=medium group=FSSO_NoNetscape service=tcp/7624 proto=6 eventtype=app-ctrl-all devid=FG1K5D3I15800570 dstintf=port25 applist=BlockYouTube msg=Network.Service: SSL_TLSv1.2, dstport=51229 type=utm dtime=2017-04-10 20:44:54 devname=HA-Group dstname=139.59.64.226 appid=41540 sessionid=847504567 profiletype=applist user=NWEA-DT srcintf=port28 srcip=10.4.48.48 level=information url=/ appcat=Network.Service srcport=49567 logid=1059028704 subtype=app-ctrl time=20:44:54 action=pass itime_t=1491875094 hostname=Just Proxy VPN policyid=83
Thanks,
Michelle
