<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: url blocking in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550103#M4801</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304428"&gt;@cylusaragao&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;URL filtering is a Layer 7 mechanism and Cortex operates on Layer 3. For IPs we can suggest using Cortex XDR host firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For URLs, there is no mechanism as such to block the URL. There is one method to create BIOC rules for incoming, outgoing and failed network connections(do not add the raw packets), and then add the domains to the list. Once created, you can add the BIOC to restrictions profiles.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note, we work on process instances termination and not network termination. Hence the above mentioned step is regressive as any network connection made using browsers for the URL will kill the browser itself and not just the network connection. As a result, all other browser tabs will also shutdown. As a result, this is can be done for 1 or 2 URLs but not a very recommended action. It is recommended to setup a firewall configuration for URL filtering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jul 2023 01:03:56 GMT</pubDate>
    <dc:creator>neelrohit</dc:creator>
    <dc:date>2023-07-20T01:03:56Z</dc:date>
    <item>
      <title>url blocking</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550042#M4795</link>
      <description>&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Tradução"&gt;&lt;SPAN class="Y2IQFc"&gt;How do I block a specific url using edl?&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:11:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550042#M4795</guid>
      <dc:creator>cylusaragao</dc:creator>
      <dc:date>2023-07-19T17:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: url blocking</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550043#M4796</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304428"&gt;@cylusaragao&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you configure the Cortex XDR based EDL on firewalls, the firewalls start syncing the data accumulated in form of IPs and URLs from the Cortex XDR EDL list. This list is populated by security investigators and administrators who were able to find some malicious IPs and URL connection from the endpoints during the course of investigation and/or threat hunting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When these IPs and URLs are added to the list, the firewalls(if configured) fetch the data from the Cortex XDR locations where the EDLs are hosted. Generally these EDL location are in format mentioned below:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%" height="57px"&gt;&lt;A href="https://edl-&amp;lt;subdomain&amp;gt;.xdr.&amp;lt;region&amp;gt;.paloaltonetworks.com/block_list?type=ip" target="_blank"&gt;https://edl-&amp;lt;subdomain&amp;gt;.xdr.&amp;lt;region&amp;gt;.paloaltonetworks.com/block_list?type=ip&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://edl-&amp;lt;subdomain&amp;gt;.xdr.&amp;lt;region&amp;gt;.paloaltonetworks.com/block_list?type=domain" target="_blank"&gt;https://edl-&amp;lt;subdomain&amp;gt;.xdr.&amp;lt;region&amp;gt;.paloaltonetworks.com/block_list?type=domain&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;Once the firewalls get the IP and domains from the EDL, any network connection associated to those IP and URLs are blocked for all the endpoints which are connected to the firewalls configured with the EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:42:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550043#M4796</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-07-19T17:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: url blocking</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550048#M4797</link>
      <description>&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Tradução"&gt;&lt;SPAN class="Y2IQFc"&gt;I don't have a firewall, is there a way to configure the edl directly in the cortex?&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 19 Jul 2023 18:07:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550048#M4797</guid>
      <dc:creator>cylusaragao</dc:creator>
      <dc:date>2023-07-19T18:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: url blocking</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550103#M4801</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304428"&gt;@cylusaragao&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;URL filtering is a Layer 7 mechanism and Cortex operates on Layer 3. For IPs we can suggest using Cortex XDR host firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For URLs, there is no mechanism as such to block the URL. There is one method to create BIOC rules for incoming, outgoing and failed network connections(do not add the raw packets), and then add the domains to the list. Once created, you can add the BIOC to restrictions profiles.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note, we work on process instances termination and not network termination. Hence the above mentioned step is regressive as any network connection made using browsers for the URL will kill the browser itself and not just the network connection. As a result, all other browser tabs will also shutdown. As a result, this is can be done for 1 or 2 URLs but not a very recommended action. It is recommended to setup a firewall configuration for URL filtering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 01:03:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550103#M4801</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-07-20T01:03:56Z</dc:date>
    </item>
  </channel>
</rss>

