<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I use a wildcard in an FQDN object? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-a-wildcard-in-an-fqdn-object/m-p/473717#M103317</link>
    <description>&lt;P&gt;Having an issue logging into an online marketing screen tool called screencloud.&amp;nbsp; The browser throws a CORS error once they hit login and the web application throws Unexpected_API_Result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only way for our marketing staff to sign into this specific service is to use their personal device or cell phone.&amp;nbsp; Any company equipment either on site or on global protect will not allow them to log in.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm thinking its the decryption policy.&amp;nbsp; I want to put a negate for an object group that contains all of the FQDNs that the company has provided.&amp;nbsp; They are saying this is the list below, but I'm really thinking its not possible to use a wildcard character is it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;What are the domains &amp;amp; servers I need to whitelist?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Here is the full list of servers/domains you need to whitelist:&lt;/P&gt;&lt;P&gt;*.screen.cloud&lt;/P&gt;&lt;P&gt;*.screencloud.com&lt;/P&gt;&lt;P&gt;*.firebase.com&lt;/P&gt;&lt;P&gt;*.googleapis.com&lt;/P&gt;&lt;P&gt;*.gstatic.com&lt;/P&gt;&lt;P&gt;*.s3.amazonaws.com&lt;/P&gt;&lt;P&gt;*.cloudfront.net&lt;/P&gt;&lt;P&gt;*.screencloudapp.com&lt;/P&gt;&lt;P&gt;*.imgix.net&lt;/P&gt;&lt;P&gt;*.sentry.io&lt;/P&gt;&lt;P&gt;*.screencloudapps.com&lt;/P&gt;&lt;P&gt;*.api.filepicker.io&lt;/P&gt;&lt;P&gt;*.assets.filepicker.io&lt;/P&gt;&lt;P&gt;*.filepicker.io&lt;/P&gt;&lt;P&gt;*.datadoghq.com&lt;/P&gt;&lt;P&gt;*.filestackapi.com&lt;/P&gt;&lt;P&gt;Also, the ports we use are&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;80&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;443&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2022 17:34:03 GMT</pubDate>
    <dc:creator>ksauer507</dc:creator>
    <dc:date>2022-03-16T17:34:03Z</dc:date>
    <item>
      <title>Can I use a wildcard in an FQDN object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-a-wildcard-in-an-fqdn-object/m-p/473717#M103317</link>
      <description>&lt;P&gt;Having an issue logging into an online marketing screen tool called screencloud.&amp;nbsp; The browser throws a CORS error once they hit login and the web application throws Unexpected_API_Result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only way for our marketing staff to sign into this specific service is to use their personal device or cell phone.&amp;nbsp; Any company equipment either on site or on global protect will not allow them to log in.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm thinking its the decryption policy.&amp;nbsp; I want to put a negate for an object group that contains all of the FQDNs that the company has provided.&amp;nbsp; They are saying this is the list below, but I'm really thinking its not possible to use a wildcard character is it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;What are the domains &amp;amp; servers I need to whitelist?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Here is the full list of servers/domains you need to whitelist:&lt;/P&gt;&lt;P&gt;*.screen.cloud&lt;/P&gt;&lt;P&gt;*.screencloud.com&lt;/P&gt;&lt;P&gt;*.firebase.com&lt;/P&gt;&lt;P&gt;*.googleapis.com&lt;/P&gt;&lt;P&gt;*.gstatic.com&lt;/P&gt;&lt;P&gt;*.s3.amazonaws.com&lt;/P&gt;&lt;P&gt;*.cloudfront.net&lt;/P&gt;&lt;P&gt;*.screencloudapp.com&lt;/P&gt;&lt;P&gt;*.imgix.net&lt;/P&gt;&lt;P&gt;*.sentry.io&lt;/P&gt;&lt;P&gt;*.screencloudapps.com&lt;/P&gt;&lt;P&gt;*.api.filepicker.io&lt;/P&gt;&lt;P&gt;*.assets.filepicker.io&lt;/P&gt;&lt;P&gt;*.filepicker.io&lt;/P&gt;&lt;P&gt;*.datadoghq.com&lt;/P&gt;&lt;P&gt;*.filestackapi.com&lt;/P&gt;&lt;P&gt;Also, the ports we use are&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;80&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;443&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 17:34:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-a-wildcard-in-an-fqdn-object/m-p/473717#M103317</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2022-03-16T17:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use a wildcard in an FQDN object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-a-wildcard-in-an-fqdn-object/m-p/473885#M103327</link>
      <description>&lt;P&gt;You can not use wildcard FQDN address objects because the PA must resolve the IPs to be able to apply them in a rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, you can create wildcard URL objects to match paths in the decryption rules:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Objects-&amp;gt;Custom Objects-&amp;gt;URL Category-&amp;gt;[DND-URLs]&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp; &amp;nbsp; example.com/&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp; &amp;nbsp; *.example.com/&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Policies-&amp;gt;Decryption-&amp;gt;[Do-Not-Decrypt-My-Dest]&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp; &amp;nbsp; src-zone=Trusted, dst-zone=Untrusted, url-category=[DND-URLs], action=no-decrypt&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 23:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-a-wildcard-in-an-fqdn-object/m-p/473885#M103327</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-16T23:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use a wildcard in an FQDN object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-a-wildcard-in-an-fqdn-object/m-p/474088#M103344</link>
      <description>&lt;P&gt;Ah great idea!&amp;nbsp; I created a new decryption policy above our current one set to no-decrypt for a new URL Category.&amp;nbsp; That seems to work!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, I'll mark that as a solution!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 16:08:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-a-wildcard-in-an-fqdn-object/m-p/474088#M103344</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2022-03-17T16:08:53Z</dc:date>
    </item>
  </channel>
</rss>

