<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL allow list for some of the subdomains in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467534#M102795</link>
    <description>&lt;P&gt;Which PANOS are you running? As said above, generic block takes precedence over specific allow. See&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC &lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The advise was to put your generic block in a block URL category, then in Objects -&amp;gt; Security Profiles -&amp;gt; URL Filtering add an allow in the Override tab for the specific URL. I recently upgraded from 8.1.x to a 9.1.x release and that entire tab seems to have disappeared... So I'm not quite sure how you would allow a more specific now...&lt;/P&gt;</description>
    <pubDate>Tue, 22 Feb 2022 16:26:59 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2022-02-22T16:26:59Z</dc:date>
    <item>
      <title>URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467492#M102788</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to limit the user to access the company's sharepoint only, but not other sharepoint from other tenant or even the sharepoint from personal account. Then I found the below KB (section 6) and show how to use allow list in the URL filtering profile to block *.sharepoint.com but allow company.sharepoint.com. But I cannot find the allow list section in PAN-OS 10.x, so anyone know how to configure the URL filtering profile to allow some subdomains (say companyA.sharepoint.com and companyA-myfiles.sharepoint.com) but not other sharepoint domain (*.sharepoint.com)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTDCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTDCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alex Tsang&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 14:48:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467492#M102788</guid>
      <dc:creator>alextsa</dc:creator>
      <dc:date>2022-02-22T14:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467514#M102789</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/178061"&gt;@alextsa&lt;/a&gt;&amp;nbsp;There is no specific allow/block lists as such. You create a custom URL categories in "&lt;SPAN&gt;Objects &amp;nbsp;&amp;gt; Custom Objects &amp;gt; URL Category". One for the custom URLs you like to block and one for allow. Then under your URL filtering profile, you assigned the required actions - block and alert respectively.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:44:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467514#M102789</guid>
      <dc:creator>batd2</dc:creator>
      <dc:date>2022-02-22T15:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467522#M102791</link>
      <description>&lt;P&gt;Note that block takes precedence over allow though, so a generic block *.sharepoint.com/ filter will block the company Sharepoint even though acme.sharepoint.com/ is in an allow URL category.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467522#M102791</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-02-22T15:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467524#M102793</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130874"&gt;@batd2&lt;/a&gt;&amp;nbsp; Thanks, and I have tried to create two custom category - one is *.sharepoint.com and one contain companyA.sharepoint.com and companyA-myfiles.sharepoint.com, then added them to a URL filtering profile with block action for *.sharepoint.com and allow for companyA.sharepoint.com. But the result is all subdomain belongs to sharepoint.com are block even companyA one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 16:04:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467524#M102793</guid>
      <dc:creator>alextsa</dc:creator>
      <dc:date>2022-02-22T16:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467534#M102795</link>
      <description>&lt;P&gt;Which PANOS are you running? As said above, generic block takes precedence over specific allow. See&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC &lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The advise was to put your generic block in a block URL category, then in Objects -&amp;gt; Security Profiles -&amp;gt; URL Filtering add an allow in the Override tab for the specific URL. I recently upgraded from 8.1.x to a 9.1.x release and that entire tab seems to have disappeared... So I'm not quite sure how you would allow a more specific now...&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 16:26:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467534#M102795</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-02-22T16:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467543#M102796</link>
      <description>&lt;P&gt;I am using 10.0&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 16:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467543#M102796</guid>
      <dc:creator>alextsa</dc:creator>
      <dc:date>2022-02-22T16:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467556#M102800</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/178061"&gt;@alextsa&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Have you look at "HTTP Header Insertion" feature - &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/http-header-insertion" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/http-header-insertion&lt;/A&gt; it might help you to achive that you want. However it requires SSL decryption in order for the firewall to inspect HTTP headers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More simple solution would be to use custom URL categories&lt;/P&gt;
&lt;P&gt;- Create URL custom category listing all sharepoints you want to allow&lt;/P&gt;
&lt;P&gt;- Use this URL category as matching criteria for allow rule (service/url tab in the gui)&lt;/P&gt;
&lt;P&gt;- Set URL profile profile for that rule that does not has any URL custom category (action set to none)&lt;/P&gt;
&lt;P&gt;- Create URL custom category listing any other sharepoint that you want to block (including wildcard)&lt;/P&gt;
&lt;P&gt;- Create URL filtering profile and set action to block for the above custom category&lt;/P&gt;
&lt;P&gt;- Use this URL filtering profile in any other rule that is allowing generic internet access - that should be below the specific rule you create for allowing access to specific sharepoint&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend to define the allow rule to be more specific by configuring destination addresses (you can get from internet ip range that MS is using for sharepoint)&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 17:10:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467556#M102800</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-02-22T17:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467566#M102801</link>
      <description>&lt;P&gt;Thanks Astardzhiev&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried HTTP Header Insertion and O365 Consumer and Enterprise Access App-ID, it can help when the O365/sharepoint/onedrive that need to go thru login process. But it cannot control when the user get a sharepoint/onedrive link that don't need login, so we need to control in the URL side to distinguish it is company's tenant or not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 17:30:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467566#M102801</guid>
      <dc:creator>alextsa</dc:creator>
      <dc:date>2022-02-22T17:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: URL allow list for some of the subdomains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467679#M102806</link>
      <description>&lt;P&gt;So this is extremely frustrating as it looks like PA has completely removed URL filtering overrides. In particular for me as I had multiple specific overrides which are now gone... I found a PA KB article on it here, but the resolution is completely wrong, as you have found out.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UtaCAE" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UtaCAE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like the only way to do it now would be create a Custom Object -&amp;gt; URL Category for the specific allow rule, create a Security policy allowing internet access and add that URL Category as a parameter in the Service/URL Category tab. Then create another Internet access rule with your general URL filtering setup that has the overall block. That is just a completely broken way to do it... I would open a support ticket and complain.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 23:39:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-for-some-of-the-subdomains/m-p/467679#M102806</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-02-22T23:39:51Z</dc:date>
    </item>
  </channel>
</rss>

