<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: using url categories in security rule base blocks allowed traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14591#M10719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way URL Filtering logs will be created is if we have a URL Filtering Profile attached to the rule passing the traffic and the action is set to anything but Allow. (Alert, Block)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Jul 2015 02:57:52 GMT</pubDate>
    <dc:creator>mmmccorkle</dc:creator>
    <dc:date>2015-07-27T02:57:52Z</dc:date>
    <item>
      <title>using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14585#M10713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a security rulebase which is causing some bizarre issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;rule 1:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;trust to untrust&lt;/LI&gt;&lt;LI&gt;service: tcp-80&lt;/LI&gt;&lt;LI&gt;url category: online-storage&lt;/LI&gt;&lt;LI&gt;url filtering profile: alert-all&lt;/LI&gt;&lt;LI&gt;allow&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;rule 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;trust to untrust&lt;/LI&gt;&lt;LI&gt;service: tcp-80&lt;/LI&gt;&lt;LI&gt;url category: /&lt;/LI&gt;&lt;LI&gt;url filtering profile: alert-all&lt;/LI&gt;&lt;LI&gt;allow&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when we do some web traffic to &lt;SPAN style="text-decoration: underline;"&gt;www.bing.com&lt;/SPAN&gt; we get 2 different type of results&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;A) we hit rule 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;traffic logs show: allow&lt;/P&gt;&lt;P&gt;url filtering logs show: category = search-engines - action: alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;B) we hit rule 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;traffic logs show: allow&lt;/P&gt;&lt;P&gt;url filtering logs show: category = &lt;EM&gt;any&lt;/EM&gt; (??) - action: block&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what I think is happening in situation B is: Traffic is hitting rule 1, and because at this stage the PaloAlto does not know the url category it will allow traffic through this rule (zone and service are a hit). After some packets the url category is known as search-engines =&amp;gt; this means the traffic is actually not allowed by rule 1 and thus traffic is dropped (even though there is a rule 2 which would have allowed this traffic!). The category = "any" in the url filtering logs is just some strange behaviour of the PaloAlto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I know this rulebase does not make sence, but it's just a recap of what is happening. The actual rules involve different user-groups and allowed applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question is:&lt;/P&gt;&lt;P&gt;Anybody else find this kind of behaviour.&lt;/P&gt;&lt;P&gt;Why is traffic sometimes hitting rule 1, and sometimes rule 2?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2015 14:02:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14585#M10713</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2015-07-23T14:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14586#M10714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This may have already been mentioned, but I'd highly suggest you use the URL Filtering profile categories to filter categories instead of putting it into that portion of the rule itself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2015 21:37:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14586#M10714</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-07-23T21:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14587#M10715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;using them in the rule is a way to get around paying for the service.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Jul 2015 22:03:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14587#M10715</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-07-25T22:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14588#M10716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What's the intent of using a URL Category in security policy in conjunction with a URL Profile?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Jul 2015 22:05:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14588#M10716</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-07-25T22:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14589#M10717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe that the engine is still active, we just have to create our own custom categories instead of using the pre-defined ones with the purchased license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Jul 2015 23:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14589#M10717</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-07-25T23:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14590#M10718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't keep it straight if using it in security policy either doesn't create a URL log or doesn't allow you to use a URL response page, but I know it's one of them as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Jul 2015 02:11:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14590#M10718</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-07-26T02:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14591#M10719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way URL Filtering logs will be created is if we have a URL Filtering Profile attached to the rule passing the traffic and the action is set to anything but Allow. (Alert, Block)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jul 2015 02:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14591#M10719</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-07-27T02:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14592#M10720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been investigating this issue with PaloAlto tech support and we found the issue.&lt;/P&gt;&lt;P&gt;We've been able to track the trigger condition down to safe search enforcement setting on the URL profile. For some reason, the string "FORM=IE" from the URL will trigger this behavior. So for some reason this would make it so search traffic to BING sometimes hit rule 1, and sometimes hit rule 2. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I do agree that using URL categories in the rulebase is just asking for trouble.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Aug 2015 08:05:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14592#M10720</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2015-08-03T08:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: using url categories in security rule base blocks allowed traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14593#M10721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear&lt;/P&gt;&lt;P&gt;Please note that: using url categories in a security policy, instead of a security profile does NOT work if you do not have a license.&lt;/P&gt;&lt;P&gt;You still need an active license to be able to use url categories.&lt;/P&gt;&lt;P&gt;You do not need a license to use custom url categories, which you can then use in security policies as well as in security profiles.&lt;/P&gt;&lt;P&gt;The use in policy or profile has nothing to do with license.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Aug 2015 08:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-url-categories-in-security-rule-base-blocks-allowed/m-p/14593#M10721</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2015-08-04T08:25:56Z</dc:date>
    </item>
  </channel>
</rss>

