<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newly Registered Domain Access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561112#M113716</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You have two options for this one:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Create a DNS Exception entry for the domain under the associated anti-spyware profile that the user's traffic is hitting. This will allow them to access that particular domain, but it does require a commit on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. In the event that you start running into this more regularly, you&amp;nbsp;&lt;EM&gt;could&amp;nbsp;&lt;/EM&gt;create a external dynamic list or URLs and use that in an override policy to allow users to a subset of domains. The benefit of this is that you won't need to commit to make changes.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Oct 2023 13:15:17 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-10-10T13:15:17Z</dc:date>
    <item>
      <title>Newly Registered Domain Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561102#M113714</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;We have a request from customer to get access to a newly registered site. After we allowed access to the URL, we see the drop logs due to Sinkhole configuration. Threat Type says Spyware and DNS Policy is configured for newly registered domains as Sinkhole by Default. So this is expected.&lt;/P&gt;
&lt;P&gt;But is there any other way i can allow access to this newly registered site without changing the DNS policy? As it will take around 30days for PA to update the URLs is what i read somewhere.&lt;/P&gt;
&lt;P&gt;Any suggestions on this please?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 11:34:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561102#M113714</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-10-10T11:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Newly Registered Domain Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561112#M113716</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You have two options for this one:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Create a DNS Exception entry for the domain under the associated anti-spyware profile that the user's traffic is hitting. This will allow them to access that particular domain, but it does require a commit on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. In the event that you start running into this more regularly, you&amp;nbsp;&lt;EM&gt;could&amp;nbsp;&lt;/EM&gt;create a external dynamic list or URLs and use that in an override policy to allow users to a subset of domains. The benefit of this is that you won't need to commit to make changes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 13:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561112#M113716</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-10-10T13:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Newly Registered Domain Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561377#M113751</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thank you for the response.&lt;/P&gt;
&lt;P&gt;May be a silly question. I understood EDL but may i know what this "&lt;SPAN&gt;use that in an override policy to allow users to a subset of domains" mean?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 05:11:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561377#M113751</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-10-12T05:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Newly Registered Domain Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561461#M113766</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You can use the EDL either in your security rulebase or your url-filtering profiles to quickly allow users access to identified domains that they may need access to. The benefit of using an EDL is that it dynamically updates, so you don't have to worry about needing to do a commit on the firewall for the exception to take effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As an example I have a security entry that uses a "Bypass-Restrictions" category as match criteria, and that "Bypass-Restrictions" is just the EDL. Then in that security entry I have a url-filtering profile that simply alerts on all categories. This allows anyone access to that rule and any domain in that rule to be accessible.&lt;/P&gt;
&lt;P&gt;The primary benefit is that I can dynamically add domains to this list without needing to actually commit any changes on the firewall due to the EDL driving the domains. This also allows me to give certain individuals access to manage the EDL without giving them any access to the firewall itself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 13:10:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newly-registered-domain-access/m-p/561461#M113766</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-10-12T13:10:09Z</dc:date>
    </item>
  </channel>
</rss>

