<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow a more specific path of a Blocked URL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/458841#M101942</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to determine if this is possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are blocking abc.company.com via an entry in a custom url category which is applied to the internet policy via a URL filtering profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to allow abc.company.com/specificpath while still blocking all other paths.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing I've tried works. We have a whitelist rule above the main internet rule that we can put URLs in but I cannot get the firewall to match on the domain/path. Only on the domain.&amp;nbsp; So when I put the domain/path into the override rule, it doesn't match and continues on down to the main internet rule where it gets blocked.&amp;nbsp; Likewise, I have tried putting the domain/path into the override tab of the URL filtering profile directly and that doesn't work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can the firewall match against domain/path or does only match against the domain and subdomain?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any insight anyone might have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jan 2022 21:18:33 GMT</pubDate>
    <dc:creator>epeeler</dc:creator>
    <dc:date>2022-01-14T21:18:33Z</dc:date>
    <item>
      <title>Allow a more specific path of a Blocked URL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/458841#M101942</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to determine if this is possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are blocking abc.company.com via an entry in a custom url category which is applied to the internet policy via a URL filtering profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to allow abc.company.com/specificpath while still blocking all other paths.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing I've tried works. We have a whitelist rule above the main internet rule that we can put URLs in but I cannot get the firewall to match on the domain/path. Only on the domain.&amp;nbsp; So when I put the domain/path into the override rule, it doesn't match and continues on down to the main internet rule where it gets blocked.&amp;nbsp; Likewise, I have tried putting the domain/path into the override tab of the URL filtering profile directly and that doesn't work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can the firewall match against domain/path or does only match against the domain and subdomain?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any insight anyone might have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 21:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/458841#M101942</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2022-01-14T21:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Allow a more specific path of a Blocked URL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/458887#M101948</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8533"&gt;@epeeler&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Do you have decryption enabled on this traffic so that the firewall can actually see the full URL?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jan 2022 06:41:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/458887#M101948</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-15T06:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: Allow a more specific path of a Blocked URL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/459355#M101988</link>
      <description>&lt;P&gt;I was trying to something similar before and the simple answer is that you can not using a custom URL category alone. When a URL matches multiple categories the most severe action takes precedence. See the following:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you need to have abc.company.com in your block customer category. The put&amp;nbsp;&lt;SPAN&gt;abc.company.com/specific path in the override list of the Security Profiles -&amp;gt; URL Filtering profile applied to your Security Policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Edit: I just re-read your post and realized you did say that you had already put the more specific in the override list. If it is blocking based on the custom block list, I would assume it is handling SSL decrypt successfully. Perhaps the pattern match in the override is not correctly terminated?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 21:43:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/459355#M101988</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-01-18T21:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Allow a more specific path of a Blocked URL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/465502#M102596</link>
      <description>&lt;P&gt;Sorry for the late reply. Thanks to both for the response and information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 14:00:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-more-specific-path-of-a-blocked-url/m-p/465502#M102596</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2022-02-14T14:00:44Z</dc:date>
    </item>
  </channel>
</rss>

