<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot block theoxymoron.xyz in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520061#M107801</link>
    <description>&lt;P&gt;No worries about all the questions.&amp;nbsp; I have a url filter policy attached to one security policy and then a different security policy to deny the IPs.&amp;nbsp; Here are some of the different ways I tried to input the URL to block it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;theoxymoron.xyz&lt;/P&gt;
&lt;P&gt;&lt;A href="https://theoxymoron.xyz" target="_blank"&gt;https://theoxymoron.xyz&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;*.theoxymoron.xyz&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there were more, but I cant remember everything I tried.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 20:02:34 GMT</pubDate>
    <dc:creator>Brandon54</dc:creator>
    <dc:date>2022-11-02T20:02:34Z</dc:date>
    <item>
      <title>Cannot block theoxymoron.xyz</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520048#M107799</link>
      <description>&lt;P&gt;Hello, I have been trying to block the site theoxymoron.xyz but can not get it to block.&amp;nbsp; I have tried URL filtering with many different versions of the URL as well as blocking the IP addresses for the site, neither of which worked for me.&amp;nbsp; We do not use decryption.&amp;nbsp; Any help would be appreciated.&amp;nbsp; Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 19:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520048#M107799</guid>
      <dc:creator>Brandon54</dc:creator>
      <dc:date>2022-11-02T19:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block theoxymoron.xyz</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520051#M107800</link>
      <description>&lt;P&gt;How exactly are you attempting to block? Does the Security Policy the traffic is going thru have a URL Filter policy attached? Have you created a custom URL Category? What format did you put the entries into the URL Category? When blocking by IP, did you put the IP in a URL category or create a separate Security Policy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for so many questions, but there are at least a half dozen different ways to filter/block sites depending on how your firewall is configured...&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 19:31:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520051#M107800</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-11-02T19:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block theoxymoron.xyz</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520061#M107801</link>
      <description>&lt;P&gt;No worries about all the questions.&amp;nbsp; I have a url filter policy attached to one security policy and then a different security policy to deny the IPs.&amp;nbsp; Here are some of the different ways I tried to input the URL to block it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;theoxymoron.xyz&lt;/P&gt;
&lt;P&gt;&lt;A href="https://theoxymoron.xyz" target="_blank"&gt;https://theoxymoron.xyz&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;*.theoxymoron.xyz&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there were more, but I cant remember everything I tried.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 20:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520061#M107801</guid>
      <dc:creator>Brandon54</dc:creator>
      <dc:date>2022-11-02T20:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block theoxymoron.xyz</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520078#M107804</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Why not block the category?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1667424781111.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45104i264BA51FE21551F8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1667424781111.png" alt="OtakarKlier_0-1667424781111.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a thought.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 21:33:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520078#M107804</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-11-02T21:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block theoxymoron.xyz</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520089#M107809</link>
      <description>&lt;P&gt;Yeah, we already had that category blocked, but that site was listed as arts and entertainment until about an hour ago.&amp;nbsp; I submitted the request to change it and it went through, now its coming up blocked.&amp;nbsp; Thanks for your help guys!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 21:46:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520089#M107809</guid>
      <dc:creator>Brandon54</dc:creator>
      <dc:date>2022-11-02T21:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block theoxymoron.xyz</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520092#M107811</link>
      <description>&lt;P&gt;So... as I said, there are many ways to do this. But if you are using a Security Policy with a URL Filter policy attached, do something like this. First you should have an existing Security Policy for your general internet bound traffic. You may want to use the "Test Policy Match" tool at the bottom of the Security Policy page to verify the traffic is actually using the intended policy. The URL Filter must also be something other than "default" as you can not change the default filter categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Policies-&amp;gt;Security&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;name=Internet Access&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;SrcZone=Trust&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;SrcAddr=CorpInternalIPs&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;DstZone=Untrust&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;DstAddr=any&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Application=any&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Service=any&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Action=Allow&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Profile Settings-&amp;gt;URL Filtering=CorpURLFilter&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then create a custom URL Category for all domains you want to block (regardless of their other automatic categorization). The entries should only be the FQDN and possibly a URL path (path will only work if you are doing SSL decryption). Without encryption it can be a bit trickier as you only have the SNI to work off of. The entries should be terminated with a slash or other delimitator to ensure variable expansion doesn't match to unintended paths (see&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oM79CAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oM79CAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;). Be sure to add both the root and wildcarded server names as the wildcard will not capture the root by itself. Don't put http/https specific resource indicators:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Objects-&amp;gt;Custom Objects-&amp;gt;URL Category&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;name=Corp-Block&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;sites=&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;theoxymoron.xyz/&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;*.theoxymoron.xyz/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now in your URL Filtering policy you should see your custom URL Category. Set the Site Access to "block":&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Objects-&amp;gt;Security Profiles-&amp;gt;URL Filtering&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;name=CorpURLFilter&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Category=&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;SPAN&gt;ᐁ Custom URL Categories:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;SPAN&gt;Corp-Block=block,block&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;SPAN&gt;...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;SPAN&gt;ᐁ Predefined Categories&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;SPAN&gt;... whatever your corporate URL categories filtering policies are...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Your Custom URL Category will override the Predefined Categories settings for anything matching your CorpBlock.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Alternatively, you can block based solely on IP address. This can be a bit more troublesome as, depending on the hosting, the website may be hosted on more IPs than the PA can track, using fast-flux DNS, may use many FQDN names, or using multiple redirects. This only works when you know the specific FQDN, unfortunately there isn't a way to wildcard address objects. Start by creating some address objects to block:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Objects-&amp;gt;Addresses&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;name=theoxymoron-xyz&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;type-&amp;gt;FQDN=theoxymoron.xyz&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;name=www-theoxymoron-xyz&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;type-&amp;gt;FQDN=&lt;A href="http://www.theoxmoron.xyz" target="_blank"&gt;www.theoxmoron.xyz&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now create a new internet-bound rule for the specific destination IPs you want to block. You don't need a URL filtering policy or other attributes on this as you will just be blocking:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Policies-&amp;gt;Security&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;name=Internet-BlockDestinations&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;SrcZone=Trust&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;SrcAddr=CorpInternalIPs&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;DstZone=Untrust&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;DstAddr=theoxymoron-xzy,www-theoxymoron-xyz&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Application=any&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Service=any&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Action=Block&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on how you have your firewall setup, and your security posture, you may want to use one or another path. I use both of the above methods (and other methods) for various categories of blocking, FQDN/domain based URL Filter based on URL-root names for general websites, Security Policy general blacklists for various other IPs and networks that should never have any traffic http/https or otherwise.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 22:07:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520092#M107811</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-11-02T22:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block theoxymoron.xyz</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520093#M107812</link>
      <description>&lt;P&gt;Yep... I tested the PA category a little bit ago, as I first started typing my above reply, and saw it as Arts&amp;amp;Entertainment as well. Showing up as Proxy Avoidance now here too.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 22:10:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-block-theoxymoron-xyz/m-p/520093#M107812</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-11-02T22:10:39Z</dc:date>
    </item>
  </channel>
</rss>

