<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom URL category issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/514223#M106770</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;I agree completely, thank you for the replies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All of the users are internal to the company, we are just trying to restrict the access based on the different locations they are in on the network. The inside and outside references are to a secure vlan (inside) and normal user (outside). The different URI locations are for transferring files in and out of the secure environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I would have ended up with a novel trying to explain that without your statement referring to the inbound URL filtering. I had not even thought of it as inbound filtering, I was looking at it all from the users side. The only thing that is causing me issues, right now, is trying to block access to the rest of the site and only allowing access to the specific URIs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2022 03:00:55 GMT</pubDate>
    <dc:creator>BruceBennett</dc:creator>
    <dc:date>2022-09-08T03:00:55Z</dc:date>
    <item>
      <title>Custom URL category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/513670#M106664</link>
      <description>&lt;P&gt;I have read through a number of URL category issues, but I just cannot find something like this and I am baffled so far. I have two users, inside and outside, that access a certain internal webserver. What I am trying to do is the following.&lt;/P&gt;
&lt;P&gt;outside:&lt;/P&gt;
&lt;P&gt;allow:&amp;nbsp;a.b.com/sites/outside and a.b.com/sites/common&lt;/P&gt;
&lt;P&gt;block: a.b.com (the rest of the site)&lt;/P&gt;
&lt;P&gt;inside:&lt;/P&gt;
&lt;P&gt;allow:&amp;nbsp;a.b.com (the rest of the site), including a.b.com/sites/inside and a.b.com/sites/common (I know they are part of the shorter domain entry)&lt;/P&gt;
&lt;P&gt;block:&amp;nbsp;a.b.com/sites/outside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Every time I add the root of the site to the custom categories it messes everything else up that is in place and outside is blocked to everything and inside is allowed access to&amp;nbsp;a.b.com/sites/outside. It is like adding in the root overrides everything and the more detailed entries are ignored.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where I am right now: I am blocking all other categories as they are not necessary as this is pointing to an inside server.&amp;nbsp;I have four custom categories that I am trying in various combinations to resolve this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cat-outside (a.b.com/sites/outside)&lt;/P&gt;
&lt;P&gt;cat-inside (a.b.com/sites/inside)&lt;/P&gt;
&lt;P&gt;cat-common (a.b.com/sites/common)&lt;/P&gt;
&lt;P&gt;cat-site (a.b.com)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I delete cat-site, I am getting a good block and allow for the extended URI entries and both users can also access the root, a.b.com/. When I add in a block for outside for the cat-site, outside loses access to common and outside. It appears that cat-site is overriding the other custom categories. Same experience for inside, I add cat-site allow, and it now has access to outside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anyway to prioritize the category with more descriptive entries over the more generic?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 22:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/513670#M106664</guid>
      <dc:creator>BruceBennett</dc:creator>
      <dc:date>2022-08-31T22:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/513749#M106682</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I know this is probably not what you want to hear, but URL filtering inbound is not a great solution. Any chance they can VPN in? Also verify that the different categories are not in the same Policy and the policies are configured correctly.&lt;/P&gt;
&lt;P&gt;Good luck.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 15:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/513749#M106682</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-01T15:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/513770#M106687</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43551"&gt;@BruceBennett&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Seconding&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;, but I'll also offer the option of creating a custom threat signature that you could use and apply to each subset. I'm actually not a fan of using the firewall for stuff like this. A load balancer like NGINX can do stuff like this easily and would be a more appropriate solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 18:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/513770#M106687</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-09-01T18:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/514223#M106770</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;I agree completely, thank you for the replies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All of the users are internal to the company, we are just trying to restrict the access based on the different locations they are in on the network. The inside and outside references are to a secure vlan (inside) and normal user (outside). The different URI locations are for transferring files in and out of the secure environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I would have ended up with a novel trying to explain that without your statement referring to the inbound URL filtering. I had not even thought of it as inbound filtering, I was looking at it all from the users side. The only thing that is causing me issues, right now, is trying to block access to the rest of the site and only allowing access to the specific URIs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 03:00:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/514223#M106770</guid>
      <dc:creator>BruceBennett</dc:creator>
      <dc:date>2022-09-08T03:00:55Z</dc:date>
    </item>
  </channel>
</rss>

