<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Blocking not working in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/452510#M1408</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Sometimes, it works after deleting cache and cooking from the history. You could try. I loved your post so much I became a fan of you, promise that you will continue to share such good and knowledgeable posts even further, we will be waiting for your post thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Dec 2021 17:10:24 GMT</pubDate>
    <dc:creator>mabelgoodrich</dc:creator>
    <dc:date>2021-12-27T17:10:24Z</dc:date>
    <item>
      <title>URL Blocking not working</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/411800#M1164</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Can anyone explain why this doesn't work?&lt;/P&gt;&lt;P&gt;I added&amp;nbsp;misoft5.s3.us-east-2.amazonaws.com and&amp;nbsp;misoft5.s3.us-east-2.amazonaws.com/* to my blocked URL list.&lt;/P&gt;&lt;P&gt;If I type in&amp;nbsp;misoft5.s3.us-east-2.amazonaws.com in a browser I get the BLOCKED page. All is well.&lt;/P&gt;&lt;P&gt;But the users are clicking on a bad link,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://misoft5.s3.us-east-2.amazonaws.com/login.mcrs0ftonline.com.common.oauth2verifyoutlook.authcommon_client_id7.html" target="_blank"&gt;https://misoft5.s3.us-east-2.amazonaws.com/login.mcrs0ftonline.com.common.oauth2verifyoutlook.authcommon_client_id7.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And that is NOT blocked. WHY NOT???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I seem to have this problem every time I block an URL, I feel like I have to add the domain name 5 different ways just so maybe it will be blocked.&lt;/P&gt;&lt;P&gt;I appreciate any help or guidance with this.&lt;/P&gt;&lt;P&gt;I do not have SSL decryption turned on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 15:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/411800#M1164</guid>
      <dc:creator>MatsApplesauce</dc:creator>
      <dc:date>2021-06-08T15:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: URL Blocking not working</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/411935#M1166</link>
      <description>&lt;P&gt;Full FQDN blocking on SSL encrypted websites is only possible if the Web Browser being used declares it in the Server Name Indication (SNI) extension which is optional, or if it matches literally with the CN presented in the Server's Certificate. Besides the Web Browser choosing not to expose the FQDN in the SNI, there are two other situations that can prevent URL Filtering matching:&lt;BR /&gt;1. The browser in use is Google Chrome, and the connection is established using the QUIC protocol instead of using HTTP(S). The solution is to create a Security Policy at the top of your security policy set blocking application 'quic'.&lt;/P&gt;
&lt;P&gt;2. The browser in use is encrypting the Client Hello (ECH) or encrypting the SNI (also known as ESNI), which are options in TLSv1.3. In that case you will not be able to read the SNI and you may need to resort into taking a decision based on the validity of the Root CA signer. You can set a decryption profile without rolling out SSL Decryption, and check with a no-decrypt Decryption Policy to see if the root CA is trusted, and if not, block the connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best way to determine what situation you're encountering is to run a packet capture of one of your user's traffic being allowed.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 23:59:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/411935#M1166</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2021-06-11T23:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: URL Blocking not working</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/412342#M1167</link>
      <description>&lt;P&gt;Thank you Mivaldi!&lt;/P&gt;&lt;P&gt;A tad more complex than I thought it would be, but thank you very much for your detailed answer.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 12:27:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/412342#M1167</guid>
      <dc:creator>MatsApplesauce</dc:creator>
      <dc:date>2021-06-10T12:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: URL Blocking not working</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/452510#M1408</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Sometimes, it works after deleting cache and cooking from the history. You could try. I loved your post so much I became a fan of you, promise that you will continue to share such good and knowledgeable posts even further, we will be waiting for your post thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 17:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/452510#M1408</guid>
      <dc:creator>mabelgoodrich</dc:creator>
      <dc:date>2021-12-27T17:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: URL Blocking not working</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/453112#M1419</link>
      <description>&lt;P&gt;1.The browser in use is Google Chrome, and the connection is established using the QUIC protocol instead of using HTTP(S). The solution is to create a Security Policy at the top of your security policy set blocking application 'quic'.&lt;/P&gt;
&lt;P&gt;2. The browser in use is encrypting the Client Hello (ECH) or encrypting the SNI (also known as ESNI), which are options in TLSv1.3. In that case you will not be able to read the SNI and you may need to resort into taking a decision based on the validity of the Root CA signer. You can set a decryption profile without rolling out SSL Decryption, and check with a no-decrypt Decryption Policy to see if the root CA is trusted, and if not, block the connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 17:11:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/453112#M1419</guid>
      <dc:creator>Colon7879</dc:creator>
      <dc:date>2021-12-27T17:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: URL Blocking not working</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/453581#M1424</link>
      <description>&lt;P&gt;Same issue still no fix to this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 08:51:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/url-blocking-not-working/m-p/453581#M1424</guid>
      <dc:creator>Humbertoe</dc:creator>
      <dc:date>2021-12-16T08:51:13Z</dc:date>
    </item>
  </channel>
</rss>

