<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Parked domain blocked when traffic not decrypted - Custom URL categories not checked with encrypted traffic in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543532#M1339</link>
    <description>&lt;P&gt;Custom categories have higher priority than pre-defined categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 May 2023 17:09:08 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-05-26T17:09:08Z</dc:date>
    <item>
      <title>Parked domain blocked when traffic not decrypted - Custom URL categories not checked with encrypted traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543032#M1298</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have an issue while trying to whitelist a parked trusted domain&amp;nbsp;&lt;A href="https://centaur-horizon.eu/" target="_blank"&gt;https://centaur-horizon.eu/.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The traffic hits a rule with a URL filtering that has Parked set to Blocked but it also has a Custom URL Category called allow-Baseline as Allow and includes the parked domain.&lt;/P&gt;
&lt;P&gt;At first, the exception seemed to work but later we realized that for users excluded from the general decryption policy, the exception does not apply and the website appears blocked.&lt;/P&gt;
&lt;P&gt;PA seems not to consider the custom URL categories analysing encrypted traffic. in the screenshots, you can see that the detected category is different in both cases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any idea how to solve this issue while keeping the decryption exception?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 11:45:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543032#M1298</guid>
      <dc:creator>JoseCortijo</dc:creator>
      <dc:date>2023-05-23T11:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Parked domain blocked when traffic not decrypted - Custom URL categories not checked with encrypted traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543037#M1299</link>
      <description>&lt;P&gt;Do you also have *.centaur-horizon.eu/ in the custom URL category?&lt;/P&gt;
&lt;P&gt;Users are trying to access &lt;A href="http://www.centaur-horizon.eu" target="_blank" rel="noopener"&gt;www.centaur-horizon.eu&lt;/A&gt; not&amp;nbsp;centaur-horizon.eu&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1684845512623.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50298i90D8D05F9A79C994/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1684845512623.png" alt="Raido_Rattameister_0-1684845512623.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also URL Filtering Profile action "Allow" means "permit traffic but don't log under URL filtering log".&lt;/P&gt;
&lt;P&gt;Best is to use action "Alert"&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 12:43:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543037#M1299</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-23T12:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Parked domain blocked when traffic not decrypted - Custom URL categories not checked with encrypted traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543051#M1300</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244719"&gt;@JoseCortijo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;that this should be set to alert instead of allow so that the URL is still logged. Unless you truly don't want the firewall to log any URL that isn't blocked, most people would want to see where the traffic is going and would want the URL logged.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the issue that you're running into if I've read your post properly is that you're trying to allow the traffic via the same profile that you have parked domains set to blocked. The most defensive action is always going to win; so if centaur-horizon is matching Parked which you have set to Block and the custom category which is set to Alert or Allow, the traffic will be blocked because that's the most restrictive action that it matches.&lt;/P&gt;
&lt;P&gt;You'd want to create a rule above the one this traffic is currently hitting that uses a custom URL profile that matches these excluded domains. That will allow the traffic to function properly without having to worry about the fact that it'll match the Parked category.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 14:07:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543051#M1300</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-05-23T14:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Parked domain blocked when traffic not decrypted - Custom URL categories not checked with encrypted traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543531#M1338</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Finally it worked just adding both&amp;nbsp;&lt;A href="http://www.centaur-horizon.eu/" target="_blank" rel="noopener nofollow noreferrer"&gt;www.centaur-horizon.eu&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;and centaur-horizon.eu as the first redirects to the second.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;as you recommended I set the custom URL category to Alert to keep track of what is happening.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But I didn't need to create an additional policy rule, a single rule was enough once the www URL was included. now it works as expected for both encrypted and decrypted traffic.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thanks for the support.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 16:56:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543531#M1338</guid>
      <dc:creator>JoseCortijo</dc:creator>
      <dc:date>2023-05-26T16:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Parked domain blocked when traffic not decrypted - Custom URL categories not checked with encrypted traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543532#M1339</link>
      <description>&lt;P&gt;Custom categories have higher priority than pre-defined categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 17:09:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/parked-domain-blocked-when-traffic-not-decrypted-custom-url/m-p/543532#M1339</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-26T17:09:08Z</dc:date>
    </item>
  </channel>
</rss>

