<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Category of Security Policy with destination &amp;quot;Any&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477888#M103707</link>
    <description>&lt;P&gt;Dear Berger69&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I further checked the log there are traffic are 2 type of traffic.&lt;/P&gt;&lt;P&gt;-&amp;nbsp; the traffic log detail's category show "any"&lt;/P&gt;&lt;P&gt;-&amp;nbsp; the traffic log detail's category show match my custom category&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to this, the second one is the traffic what I want.&lt;/P&gt;&lt;P&gt;For the first type, may I know how PA handle it? since the traffic log mention it is allowed but it doesn't match the category. So it is dropped or pass to another rule to handle?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2022 09:14:32 GMT</pubDate>
    <dc:creator>PChow4</dc:creator>
    <dc:date>2022-04-04T09:14:32Z</dc:date>
    <item>
      <title>URL Category of Security Policy with destination "Any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477425#M103673</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a security policy as below. However, I find all traffic will go through this policy. Do you have any idea? Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source: Any&lt;/P&gt;&lt;P&gt;Destination: Any&lt;/P&gt;&lt;P&gt;Service: 443, 80 and specific port&lt;/P&gt;&lt;P&gt;URL Category: Custom (*.s3.amazonaws.com)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 03:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477425#M103673</guid>
      <dc:creator>PChow4</dc:creator>
      <dc:date>2022-04-01T03:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category of Security Policy with destination "Any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477480#M103676</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/188043"&gt;@PChow4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, with the type of policy you have written, you will see that it is showing allowed traffic logs for rest traffic also. But actually those session would only TCP and/or SSL sessions created with the destination. Once URL category is matched, the final decision will be made if traffic needs to be allow or drop. I would recommend you to verify complete traffic logs by opening it and you will see what's actually getting allowed.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 05:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477480#M103676</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2022-04-01T05:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category of Security Policy with destination "Any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477484#M103678</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. I open it and find the log type is end and allowed.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 06:30:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477484#M103678</guid>
      <dc:creator>PChow4</dc:creator>
      <dc:date>2022-04-01T06:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category of Security Policy with destination "Any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477492#M103679</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/188043"&gt;@PChow4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can verify the detailed log view of desired URL category matching traffic vs rest then you will get clarity. But again, answer to your question in one short line - the unwanted traffic matching your rule are for TCP/SSL session created with the destination. At the end, traffic will be allowed based on the matched URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POF8CAO" target="_self"&gt;Ref. article&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 06:49:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477492#M103679</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2022-04-01T06:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category of Security Policy with destination "Any"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477888#M103707</link>
      <description>&lt;P&gt;Dear Berger69&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I further checked the log there are traffic are 2 type of traffic.&lt;/P&gt;&lt;P&gt;-&amp;nbsp; the traffic log detail's category show "any"&lt;/P&gt;&lt;P&gt;-&amp;nbsp; the traffic log detail's category show match my custom category&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to this, the second one is the traffic what I want.&lt;/P&gt;&lt;P&gt;For the first type, may I know how PA handle it? since the traffic log mention it is allowed but it doesn't match the category. So it is dropped or pass to another rule to handle?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 09:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-of-security-policy-with-destination-quot-any-quot/m-p/477888#M103707</guid>
      <dc:creator>PChow4</dc:creator>
      <dc:date>2022-04-04T09:14:32Z</dc:date>
    </item>
  </channel>
</rss>

