<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Request to unblock firewall for my website in Web Proxy Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/web-proxy-discussions/request-to-unblock-firewall-for-my-website/m-p/1251789#M69</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I published my new website theaiembrace.com as I am launching my new business. It seems you have blocked outbound access to my website by firewall and DNS. Can you unblock access, please?&lt;BR /&gt;Many thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Telma&lt;/P&gt;</description>
    <pubDate>Tue, 07 Apr 2026 20:14:59 GMT</pubDate>
    <dc:creator>telminha0mermaid</dc:creator>
    <dc:date>2026-04-07T20:14:59Z</dc:date>
    <item>
      <title>Request to unblock firewall for my website</title>
      <link>https://live.paloaltonetworks.com/t5/web-proxy-discussions/request-to-unblock-firewall-for-my-website/m-p/1251789#M69</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I published my new website theaiembrace.com as I am launching my new business. It seems you have blocked outbound access to my website by firewall and DNS. Can you unblock access, please?&lt;BR /&gt;Many thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Telma&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 20:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/web-proxy-discussions/request-to-unblock-firewall-for-my-website/m-p/1251789#M69</guid>
      <dc:creator>telminha0mermaid</dc:creator>
      <dc:date>2026-04-07T20:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Request to unblock firewall for my website</title>
      <link>https://live.paloaltonetworks.com/t5/web-proxy-discussions/request-to-unblock-firewall-for-my-website/m-p/1251825#M70</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/445422675"&gt;@telminha0mermaid&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Networks firewalls are designed to proactively block access to newly registered domains (NRDs) and domains associated with dynamic DNS (DDNS) in both URL and DNS categories due to the high security risks these domains often present. This proactive blocking is a critical component of the firewall's threat prevention capabilities.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;A newly registered domain (NRD) refers to a domain that has been registered or undergone a change in ownership within the last 30 to 32 days&lt;/U&gt;&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Security Significance&lt;/STRONG&gt;&amp;nbsp;Newly registered domains are considered a "Potential Threat" category within Palo Alto Networks security classifications. This is because they are frequently created and used for malicious activities, such as phishing attacks, command and control (C2) communications, and the distribution of malware. Attackers often register new domains to launch web-based attacks, and these domains may have a short lifespan, making them challenging to detect. There is a strong correlation between newly registered domains and malicious URLs.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Palo Alto Networks Detection and Categorization&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;URL Filtering (PAN-DB):&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;URLs are categorized as&amp;nbsp;newly-registered-domain&amp;nbsp;when their registration (observed via Passive DNS) falls within the last 32 days.&lt;/LI&gt;
&lt;LI&gt;After this initial period, Palo Alto Networks' systems crawl the URL to determine if it requires re-categorization. If this process is unsuccessful, the category might be updated to&amp;nbsp;Insufficient-Content, Newly-Registered-Domain.&lt;/LI&gt;
&lt;LI&gt;By default, newly registered domains may initially be categorized as&amp;nbsp;unknown&amp;nbsp;in PAN-DB. Palo Alto Networks' analysis/threat team or automated crawlers review and classify these domains.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;STRONG&gt;DNS Security and Advanced DNS Security:&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;These services detect NRDs by monitoring specific feeds, including domain registries and registrars, and by utilizing zone files, passive DNS, and WHOIS data.&lt;/LI&gt;
&lt;LI&gt;Palo Alto Networks employs machine learning (ML) algorithms to predict and identify new malicious domains shortly after their registration, often before they are actively used in an attack.&lt;/LI&gt;
&lt;LI&gt;"Newly Registered Domains" are a specific DNS Security category (UTID: 109020001) that can be filtered in Threat logs as&amp;nbsp;&lt;EM&gt;dns-new-domain&lt;/EM&gt;&amp;nbsp;or&amp;nbsp;&lt;EM&gt;adns-new-domain&lt;/EM&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Botnet Reports:&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Traffic directed to domains registered within the past 30 days is monitored as an indicator of potential botnet activity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Best Practices and Configuration:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Recommended Action:&lt;/STRONG&gt;&amp;nbsp;For&amp;nbsp;newly-registered-domain&amp;nbsp;and&amp;nbsp;dynamic-dns&amp;nbsp;URL categories, the recommended action in URL Filtering profiles is generally to&amp;nbsp;block&amp;nbsp;access to maximize security.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Handling Unknown Sites:&lt;/STRONG&gt;&amp;nbsp;Sites not yet identified by PAN-DB (unknown&amp;nbsp;category) are also considered potential threats. While blocking is the most secure option, if business needs require allowing traffic to unknown sites, it's recommended to set the action to&amp;nbsp;alert, apply the strictest Security profiles, and thoroughly investigate any alerts.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Exceptions:&lt;/STRONG&gt;&amp;nbsp;&lt;EM&gt;&lt;U&gt;If legitimate business operations require access to specific sites within these blocked categories, administrators can create custom URL categories or specific allow rules to create exceptions. However, this should be done cautiously, often with strict security profiles applied to the allowed traffic&lt;/U&gt;&lt;/EM&gt;.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 08 Apr 2026 05:45:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/web-proxy-discussions/request-to-unblock-firewall-for-my-website/m-p/1251825#M70</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2026-04-08T05:45:29Z</dc:date>
    </item>
  </channel>
</rss>

