<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL filtering - allows blocked traffic in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233702#M6073</link>
    <description>&lt;P&gt;Yes, I have checked that already. The block rule is high up on the rule base, while the rule the traffic is hitting is at the bottom.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks for replying though.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jul 2025 08:17:46 GMT</pubDate>
    <dc:creator>Robert2</dc:creator>
    <dc:date>2025-07-10T08:17:46Z</dc:date>
    <item>
      <title>URL filtering - allows blocked traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233554#M6060</link>
      <description>&lt;P&gt;URL filtering logs show web traffic that matches a custom URL category that we use to block / deny traffic to certain malicious domains, but the traffic doesn't match&amp;nbsp; the deny rule, it matches a generic rule we have for https/http traffic.&lt;BR /&gt;&lt;BR /&gt;Why would the firewall clearly show on the URL filtering logs that it matches the URL category used for blocking but not assign that traffic to the specific rule and block the traffic.&lt;BR /&gt;&lt;BR /&gt;Anyone seen this before, my team are trying to establish is this traffic is getting through the firewalls or not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 14:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233554#M6060</guid>
      <dc:creator>Robert2</dc:creator>
      <dc:date>2025-07-08T14:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering - allows blocked traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233556#M6062</link>
      <description>&lt;P&gt;screeshot of URL filtering logs&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 15:25:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233556#M6062</guid>
      <dc:creator>Robert2</dc:creator>
      <dc:date>2025-07-08T15:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering - allows blocked traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233650#M6068</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check which security policy its hitting and then check if that policy is higher on the security policy list than the one that should apply.&lt;/P&gt;
&lt;P&gt;The firewall reads policies for matches top to bottom and left to right.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 19:43:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233650#M6068</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-07-09T19:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering - allows blocked traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233702#M6073</link>
      <description>&lt;P&gt;Yes, I have checked that already. The block rule is high up on the rule base, while the rule the traffic is hitting is at the bottom.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks for replying though.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 08:17:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233702#M6073</guid>
      <dc:creator>Robert2</dc:creator>
      <dc:date>2025-07-10T08:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering - allows blocked traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233740#M6078</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/137326"&gt;@Robert2&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you confirm the custom URL category is set to an action of block within a URL filtering profile?&lt;/P&gt;
&lt;P&gt;Furthermore, can you confirm the URL filtering profile is applied correctly (either directly or listed within a Security Profile Group) to the block rule you mentioned?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 15:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/url-filtering-allows-blocked-traffic/m-p/1233740#M6078</guid>
      <dc:creator>nohash4u</dc:creator>
      <dc:date>2025-07-10T15:24:57Z</dc:date>
    </item>
  </channel>
</rss>

