<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999354#M5295</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/320873"&gt;@ADR&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I’m experiencing the same issue with the URL:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://arabglobalscholars.org/" target="_new" rel="noopener"&gt;&lt;SPAN&gt;https&lt;/SPAN&gt;&lt;SPAN&gt;://arabglobalscholars&lt;/SPAN&gt;&lt;SPAN&gt;.org/&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;as mentioned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208635"&gt;@Rahul.Balan&lt;/a&gt; above.&lt;/P&gt;
&lt;P&gt;This issue is occurring across multiple customers.&lt;/P&gt;
&lt;P&gt;The URL is being blocked by a deny policy applied to an address object group containing multiple blacklisted static IP addresses. However, upon reviewing the blacklist, we cannot find the website's IP address within this group.&lt;/P&gt;
&lt;P&gt;If we remove the object group, the policy instead hits a specified rule.&lt;/P&gt;
&lt;P&gt;Could you please assist in resolving this?&lt;/P&gt;</description>
    <pubDate>Mon, 23 Dec 2024 17:07:36 GMT</pubDate>
    <dc:creator>RoneyRajan123</dc:creator>
    <dc:date>2024-12-23T17:07:36Z</dc:date>
    <item>
      <title>Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999229#M5283</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I’m experiencing an unusual issue with my Palo Alto firewall. This problem started about a week ago. Prior to that, the website in question was functioning properly and being handled by the appropriate security policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently, a public website is being blocked by a specific security policy in the firewall. Upon reviewing this policy, I couldn’t find the website’s address in any of the destination address groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are the details of the policy:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Source Zone:&lt;/STRONG&gt; Any&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Source Address:&lt;/STRONG&gt; Any&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Destination Zone:&lt;/STRONG&gt; Any&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Destination Address:&lt;/STRONG&gt; Static Address Object&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy Action:&lt;/STRONG&gt; Deny&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Website:&lt;/STRONG&gt;&amp;nbsp;&lt;A href="https://********.org" target="_blank" rel="noopener"&gt;https://********.org&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Websites&amp;nbsp; IPs do not appear to be part of the static address objects in the destination address lists.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interestingly, if we remove the static address object from the policy, the website works fine and is processed by the appropriate security policy.&lt;/P&gt;
&lt;P&gt;Please advise on how to resolve this issue.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225008"&gt;@ahameed&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184324"&gt;@mshamamulla&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308796"&gt;@paloalto&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 08:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999229#M5283</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2024-12-22T08:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999233#M5284</link>
      <description>&lt;P&gt;We also tried to find out those IPs in the CLI as well, however, we couldn't find it. is it a bug.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 08:18:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999233#M5284</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2024-12-22T08:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999290#M5285</link>
      <description>&lt;P&gt;I am also facing the same issue for website &lt;A href="https://arabglobalscholars.org/" target="_blank"&gt;https://arabglobalscholars.org/&lt;/A&gt; . it is getting blocked by the object group that does not contain the ip address of the website &lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 07:48:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999290#M5285</guid>
      <dc:creator>Rahul.Balan</dc:creator>
      <dc:date>2024-12-23T07:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999344#M5294</link>
      <description>&lt;P&gt;I don't know exactly what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223437"&gt;@RoneyRajan123&lt;/a&gt;'s website is, but&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208635"&gt;@Rahul.Balan&lt;/a&gt;'s website resolves to a Cloudflare proxy frontend. The indicated Security Policies blocks solely based on the destination IP address matching one included or resolved in the Address list (which may be both IP address and FQDNs which are resolved to IPs). It does not match based on the FQDN name itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cloudflare proxies act as the front end for many different FQDNs resolved to the same IP addresses. There may be a completely different FQDN address object that is resolving to the same IP as the site you are trying to access. Therefore, both destinations get blocked because both resolve to the same IP(s).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, if you have a large Address list using FQDNs, there is no good way to quickly filter to objects matching a certain IP address, but you can browse through them using the following command on the CLI:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;show dns-proxy fqdn all&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will show all FQDN address objects currently monitored and their resolved IP address(es). You can also quickly search for a particular IP using a match filter, but unfortunately, do to the way the list is formatted, it doesn't show the FQDN, you have to review the entire list manually for that.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;show dns-proxy fqdn all | match &amp;lt;IP address&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have a large number of address objects to be blocked, or FQDNs that resolve to a Cloudflare IP, consider if using a URL filter is a better option to prevent false positive blocking.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 16:13:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999344#M5294</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-12-23T16:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999354#M5295</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/320873"&gt;@ADR&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I’m experiencing the same issue with the URL:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://arabglobalscholars.org/" target="_new" rel="noopener"&gt;&lt;SPAN&gt;https&lt;/SPAN&gt;&lt;SPAN&gt;://arabglobalscholars&lt;/SPAN&gt;&lt;SPAN&gt;.org/&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;as mentioned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208635"&gt;@Rahul.Balan&lt;/a&gt; above.&lt;/P&gt;
&lt;P&gt;This issue is occurring across multiple customers.&lt;/P&gt;
&lt;P&gt;The URL is being blocked by a deny policy applied to an address object group containing multiple blacklisted static IP addresses. However, upon reviewing the blacklist, we cannot find the website's IP address within this group.&lt;/P&gt;
&lt;P&gt;If we remove the object group, the policy instead hits a specified rule.&lt;/P&gt;
&lt;P&gt;Could you please assist in resolving this?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 17:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999354#M5295</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2024-12-23T17:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999358#M5296</link>
      <description>&lt;P&gt;Does the address group contain just IP addresses? Or does it also contain FQDN address objects?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The arabglobalscholars.org FQDN resolves to 7 different Cloudflare IPs that are widely used for other FQDNs as well:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;104.21.16.1&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;104.21.32.1&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;104.21.48.1&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;104.21.64.1&lt;BR /&gt;104.21.80.1&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;104.21.96.1&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;104.21.112.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These IPs are widely used for other websites as well. I recently had a known malware FQDN switch from one IP to Cloudflare proxy on these IPs which caused a block of unrelated websites in our filtering rules.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 17:41:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999358#M5296</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-12-23T17:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999398#M5298</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223437"&gt;@RoneyRajan123&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Make sure the right Security rule is above the security rule which is blocking the website.&lt;BR /&gt;2. Even after step-1 if still the right security rule is bypassed and wrong security rule is hit then take Debug logs to understand the root cause.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-flow-basic-debugging/ta-p/545999" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-flow-basic-debugging/ta-p/545999&lt;/A&gt;&lt;/P&gt;
&lt;DIV class="UserSignature lia-message-signature"&gt;Mohammed Shamamulla&lt;BR /&gt;Technical Partner Manager | Palo Alto Networks &lt;BR /&gt;Don't forget to Like items if a post is helpful to you!&lt;BR /&gt;&lt;BR /&gt;Please help out other users and “Accept as Solution” if a post helps solve your problem !&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-and-why-to-accept-solutions/ba-p/553827" target="_blank"&gt;Read more about how and why to accept solutions.&lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 07:03:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999398#M5298</guid>
      <dc:creator>mshamamulla</dc:creator>
      <dc:date>2024-12-24T07:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999399#M5299</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804"&gt;@Adrian_Jensen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for your support.&lt;BR /&gt;I got in the solution for my issue. Actually customer also using a malicious FQDN on their address object group which was also resolved to the same IP address.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 07:08:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/999399#M5299</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2024-12-24T07:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/1235798#M6188</link>
      <description>&lt;P data-start="135" data-end="147"&gt;Hi Adrian,&lt;/P&gt;
&lt;P data-start="149" data-end="303"&gt;Another customer has reported that the FQDN &lt;STRONG data-start="193" data-end="211"&gt;"frameset.app"&lt;/STRONG&gt; is being blocked by the firewalls, even though it is not listed in our blocked IPs or&amp;nbsp;FQDN list.&lt;/P&gt;
&lt;P data-start="305" data-end="319"&gt;&lt;STRONG data-start="305" data-end="317"&gt;Details:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="320" data-end="378"&gt;
&lt;LI data-start="320" data-end="346"&gt;
&lt;P data-start="322" data-end="346"&gt;&lt;STRONG data-start="322" data-end="331"&gt;FQDN:&lt;/STRONG&gt; frameset.app&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="347" data-end="378"&gt;
&lt;P data-start="349" data-end="378"&gt;&lt;STRONG data-start="349" data-end="364"&gt;IP Address:&lt;/STRONG&gt; 76.76.21.21&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="380" data-end="479"&gt;This IP and domain are not part of our blocked lists; however, they appear to be getting blocked.&lt;/P&gt;
&lt;P data-start="481" data-end="621"&gt;Could you please help confirm whether this IP/FQDN is associated with any other malicious domains or categorized under another block list?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 18:15:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/1235798#M6188</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2025-08-11T18:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/1239318#M6363</link>
      <description>&lt;P&gt;Sorry Roney, I haven't been during PaloAlto stuff for a couple months, been busy with over issues. I can not find any conflicts with "frameset.app" on my side, but we may have completely different blocklists and data sources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When tracking these problems down, one thing you can try is to look at the PaloAlto DNS-Proxy cache and FQDN for matching IPs in other Address Objects. So frameset.app currently resolves to 76.76.21.21 for me. From the PaloAlto CLI you can run the following commands and see if there are any matches:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;show dns-proxy cache all | match 76\.76\.21\.21&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;show dns-proxy fqdn all | match 76\.76\.21\.21&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have a match then there is at least one object that the PaloAlto knows about that matches the IP. Unfortunately, the CLI output is a bit messy (particularly if you have a large number of objects), but if you can find the name then you can start searching that name to learn where it may exist in the config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 19:29:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/public-website-ips-that-is-not-a-part-of-the-address-object/m-p/1239318#M6363</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2025-10-02T19:29:10Z</dc:date>
    </item>
  </channel>
</rss>

