<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Differences between URL category and address object? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/531651#M109641</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79934"&gt;@Chacko42&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have observed Palo Alto PANOS 10.2.1 dropping the traffic even when it sees the same domain in the SNI field of the Client Hello packet, that is configured in the security policy allow rule, under URL Category field. And thus the website does not open at client's end. It is still unclear as to why the firewall is not able to match the two exactly same domains.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note that it is different from seeing in your browser "Your connection is not private" kind of message. In such case, the problem is that the SSL certificate offered by the server in response to the Client Hello packet, does not&lt;SPAN&gt;&amp;nbsp;match the name of the domain initially requested by the client. While, my scenario is different, where the website does not open at the first place and we see the traffic blocked by the interzone-default rule of Palo Alto firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any idea why does it happen?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 18 Feb 2023 19:12:29 GMT</pubDate>
    <dc:creator>RizwanJamil</dc:creator>
    <dc:date>2023-02-18T19:12:29Z</dc:date>
    <item>
      <title>Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285785#M76479</link>
      <description>&lt;P&gt;We are doing some testing with a user that is running a client and needs to get out to the internet.&lt;/P&gt;&lt;P&gt;1. We have a policy for testing and added the required FQDN address objects to the destination. This was successful.&lt;/P&gt;&lt;P&gt;2. Next, we removed the address objects from the destination (replaced that with "any") and moved them to be part of an existing URL category group. We then added this URL category group to the testing policy. This has worked for us when testing in the past, but does not work now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why would something work when added as an address object but not when it's part of a URL category group? Am I missing something?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 15:20:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285785#M76479</guid>
      <dc:creator>TLineberry</dc:creator>
      <dc:date>2019-08-29T15:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285793#M76480</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56943"&gt;@TLineberry&lt;/a&gt;&amp;nbsp;Which L7-Applications are you using in that policy?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 15:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285793#M76480</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-08-29T15:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285810#M76482</link>
      <description>&lt;P&gt;SSL&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 16:59:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285810#M76482</guid>
      <dc:creator>TLineberry</dc:creator>
      <dc:date>2019-08-29T16:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285819#M76485</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are you decrypting the traffic? If yes and you are not running version 9.0.x, the nyou will also need to add web-browsing and set the service ports to 443 and 80 for web-browsing. Also check the logs to see why its getting blocked. Could be a new application blocking the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 17:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285819#M76485</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-29T17:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285834#M76487</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are not decrypting the traffic. Checked the logs and we don't see anything, no other apps, etc. It's very odd!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just don't know why it would work when using destination address objects but not when using objects in a URL category...&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 17:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285834#M76487</guid>
      <dc:creator>TLineberry</dc:creator>
      <dc:date>2019-08-29T17:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285835#M76488</link>
      <description>&lt;P&gt;Also check the URL logs to see if its blocking on the catagory the URL is in.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 18:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285835#M76488</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-29T18:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285940#M76512</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56943"&gt;@TLineberry&lt;/a&gt;: That's expected behavior. The system needs to see the URL to match it agains your URL filter.&lt;/P&gt;&lt;P&gt;In TLS, the URL is part of the encrypted payload, if you're lucky and the server hosts multiple websites, it may use TLS-SNI. So you need to decrypt the traffic, to see the URL. When you use a FQDN address object, the palo simply does a dns forward lookup and whitelists the IP - that's independent from any URLs and works e.g. for CIFS traffic, which doesn't use URLs as well.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 06:31:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/285940#M76512</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-08-30T06:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/531651#M109641</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79934"&gt;@Chacko42&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have observed Palo Alto PANOS 10.2.1 dropping the traffic even when it sees the same domain in the SNI field of the Client Hello packet, that is configured in the security policy allow rule, under URL Category field. And thus the website does not open at client's end. It is still unclear as to why the firewall is not able to match the two exactly same domains.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note that it is different from seeing in your browser "Your connection is not private" kind of message. In such case, the problem is that the SSL certificate offered by the server in response to the Client Hello packet, does not&lt;SPAN&gt;&amp;nbsp;match the name of the domain initially requested by the client. While, my scenario is different, where the website does not open at the first place and we see the traffic blocked by the interzone-default rule of Palo Alto firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any idea why does it happen?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 19:12:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/531651#M109641</guid>
      <dc:creator>RizwanJamil</dc:creator>
      <dc:date>2023-02-18T19:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Differences between URL category and address object?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/531653#M109643</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79934"&gt;@Chacko42&lt;/a&gt;&amp;nbsp;please also note that I don't have URL filtering or SSL inspection enabled. So firewall is relying solely on the SNI information contained in the packet which is exactly the same as the one configured in the allow rule, however the firewall is still unable to match one with the other.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 20:21:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/differences-between-url-category-and-address-object/m-p/531653#M109643</guid>
      <dc:creator>RizwanJamil</dc:creator>
      <dc:date>2023-02-18T20:21:25Z</dc:date>
    </item>
  </channel>
</rss>

