<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PaloAlto Firewall App and URL Category mismatch in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516335#M107223</link>
    <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created the two deny policies (one with facebook-base application and other one with social-networking). Still traffic are allowing with internet any policy by matching URL category as any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know why still traffic bypassing these two rules? and allowing in internet policy.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If decryption is the only solution, I am thinking about basic firewall functioning..!&lt;/P&gt;</description>
    <pubDate>Thu, 29 Sep 2022 08:38:34 GMT</pubDate>
    <dc:creator>lakshmipathimurugan</dc:creator>
    <dc:date>2022-09-29T08:38:34Z</dc:date>
    <item>
      <title>PaloAlto Firewall App and URL Category mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516040#M107167</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In PA Firewall logs I am noticing the strange behaviour of the App and URL Category. I have blocked the social networking sites in the policy. But Facebook-based applications are categorized under any; sometimes it is categorized as social networking and blocking traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone face this issue before? What is the solution to fix this categorization issue?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Tue, 27 Sep 2022 08:25:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516040#M107167</guid>
      <dc:creator>lakshmipathimurugan</dc:creator>
      <dc:date>2022-09-27T08:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto Firewall App and URL Category mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516065#M107170</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210445"&gt;@lakshmipathimurugan&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for the post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The behavior you described is expected. The below KBs describe what URL category "any" means:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UP1CAM&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UP1CAM&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm08CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm08CAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your ultimate goal is to block Facebook, then I would create 2 security policies. One policy to block application: facebook-base and another to block URL category: social-networking. In this way either of the policy will be hit to deny Facebook related traffic regardless it is detected as application or URL category.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With your current policy: "Block Streaming Media-App Based" the issue I am seeing, to block this traffic, Firewall has to decode application as "facebook-base" and have enough information to categorize URL category as "social-networking". If Firewall can't categorize URL category, this policy will not be hit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your goal is to go more granular and block only some of the Facebook application, you will have to enable decryption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 13:09:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516065#M107170</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-27T13:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto Firewall App and URL Category mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516335#M107223</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created the two deny policies (one with facebook-base application and other one with social-networking). Still traffic are allowing with internet any policy by matching URL category as any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know why still traffic bypassing these two rules? and allowing in internet policy.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If decryption is the only solution, I am thinking about basic firewall functioning..!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 08:38:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516335#M107223</guid>
      <dc:creator>lakshmipathimurugan</dc:creator>
      <dc:date>2022-09-29T08:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto Firewall App and URL Category mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516562#M107277</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210445"&gt;@lakshmipathimurugan&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you confirm what actual user experience is? Where you able to confirm that Facebook traffic is not blocked? Some of the traffic will have a URL category as any until Firewall has enough traffic to go through to properly categorize it, this should however eventually result traffic being blocked by matching right policy. Before that happens some of the logs will have category any.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To block Facebook traffic, decryption is not required, the Facebook traffic will be categorized based on initial SSL handshake by looking into SNI of certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sun, 02 Oct 2022 07:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-app-and-url-category-mismatch/m-p/516562#M107277</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-10-02T07:16:56Z</dc:date>
    </item>
  </channel>
</rss>

