<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EDL and Custom URL in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-and-custom-url/m-p/507365#M187</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/178856"&gt;@Ramakrishnan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the policies if traffic log at session START is enabled, there are chances that the logs will show matching incorrect policy. This is because, when request reaches the firewall interface, the first matching policy in the set will be matched to allow traffic and create session but still at backend, firewall is checking for matching the security profile configurations. So the logs at session END will show the correct rules once all the checks are done by the firewall. Kindly refer &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm27CAC" target="_self"&gt;this article&lt;/A&gt; for more details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Coming to your 2&lt;SUP&gt;nd&lt;/SUP&gt; query that you are not able to see logs under URL filtering tabs. To view the logs, you need to make sure that URL category action is set to &lt;STRONG&gt;alert&lt;/STRONG&gt; to log the URL filtering logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jun 2022 08:59:35 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2022-06-30T08:59:35Z</dc:date>
    <item>
      <title>EDL and Custom URL</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-and-custom-url/m-p/507218#M184</link>
      <description>&lt;P&gt;Hi There,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem Statement : We have custom URL lists(To allow Azure Endpoints only), also we have EDL(With Minemeld) integrated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per our Infosec Policy we should not use Minemeld feed for Microsoft as it has some of many wildcard. So desperately creating custom URL for each MSFT end points(viz Defender, AAD heath etc,,)&amp;nbsp;&lt;/P&gt;&lt;P&gt;But some of URL is not working. I couldn't fetch the exact URL which is getting blocked(its default implementation PAN that, unlisted URLs will not show in URL filtering tab...? but in the Traffic Tab I am seeing very peculiar;&lt;/P&gt;&lt;P&gt;For example: As per below screen shot, Why session is starting the Rule which i configured and fall back to Deny (reset-both with "default deny") category showing EDL-Azure-URL(In fact we have not configured "EDL-Azure-URLs" in the policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ramakrishnan_0-1656531514731.png" style="width: 557px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42078i7FCF0E32DEEB7AE7/image-dimensions/557x223/is-moderation-mode/true?v=v2" width="557" height="223" role="button" title="Ramakrishnan_0-1656531514731.png" alt="Ramakrishnan_0-1656531514731.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ramakrishnan_1-1656531743034.png" style="width: 545px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42079i2E0DBD97C7D3912B/image-dimensions/545x254/is-moderation-mode/true?v=v2" width="545" height="254" role="button" title="Ramakrishnan_1-1656531743034.png" alt="Ramakrishnan_1-1656531743034.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ramakrishnan_2-1656531871704.png" style="width: 601px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42080iC35F7E516E1BD544/image-dimensions/601x290/is-moderation-mode/true?v=v2" width="601" height="290" role="button" title="Ramakrishnan_2-1656531871704.png" alt="Ramakrishnan_2-1656531871704.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 19:59:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-and-custom-url/m-p/507218#M184</guid>
      <dc:creator>Ramakrishnan</dc:creator>
      <dc:date>2022-06-29T19:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: EDL and Custom URL</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-and-custom-url/m-p/507365#M187</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/178856"&gt;@Ramakrishnan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the policies if traffic log at session START is enabled, there are chances that the logs will show matching incorrect policy. This is because, when request reaches the firewall interface, the first matching policy in the set will be matched to allow traffic and create session but still at backend, firewall is checking for matching the security profile configurations. So the logs at session END will show the correct rules once all the checks are done by the firewall. Kindly refer &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm27CAC" target="_self"&gt;this article&lt;/A&gt; for more details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Coming to your 2&lt;SUP&gt;nd&lt;/SUP&gt; query that you are not able to see logs under URL filtering tabs. To view the logs, you need to make sure that URL category action is set to &lt;STRONG&gt;alert&lt;/STRONG&gt; to log the URL filtering logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 08:59:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-and-custom-url/m-p/507365#M187</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2022-06-30T08:59:35Z</dc:date>
    </item>
  </channel>
</rss>

