<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why cant a URL be used directly in a policy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-cant-a-url-be-used-directly-in-a-policy/m-p/563293#M114088</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I understand that to block an individual URL it has to be in a custom category before it can be used in a policy as a destination. For my own education and curiosity, my question is why must it be in a category? What is the processing logic in the firewall that makes this a requirement?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2023 20:29:03 GMT</pubDate>
    <dc:creator>ABurger</dc:creator>
    <dc:date>2023-10-26T20:29:03Z</dc:date>
    <item>
      <title>Why cant a URL be used directly in a policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-cant-a-url-be-used-directly-in-a-policy/m-p/563293#M114088</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I understand that to block an individual URL it has to be in a custom category before it can be used in a policy as a destination. For my own education and curiosity, my question is why must it be in a category? What is the processing logic in the firewall that makes this a requirement?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 20:29:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-cant-a-url-be-used-directly-in-a-policy/m-p/563293#M114088</guid>
      <dc:creator>ABurger</dc:creator>
      <dc:date>2023-10-26T20:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why cant a URL be used directly in a policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-cant-a-url-be-used-directly-in-a-policy/m-p/563439#M114101</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/119516"&gt;@ABurger&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It would be drastically more resource intensive to check the rulebase against a single URL versus the category. On the backend PAN would have to convert every URL entry utilized in the security rulebase (or every group of URLs used in a security rulebase entry) to it's own individual category. Then you'd have to deal with the fact that URL Filtering profiles exist and wouldn't have a defined action for the dynamic category that it's creating, so it would have to assume intent (IE: If the security entry allows access to a URL, do they default to that being a category action of "allow" or "alert"?). What about credential enforcement action? This is also all negating any platform limits and the fact that any VSYS can only ever have 500 custom categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In short, it's resource intensive and doing so isn't conducive to properly following assigned profiles if it's dynamically building categories on the backend to keep overhead to a minimum. They'd need to not only give you the ability to dynamically build categories if you specified URLs in an entry, but they would also need to allow you to set URL Filtering behavior for those categories and dynamically build out additional profiles for each new entry as well.&lt;/P&gt;
&lt;P&gt;That would be an incredible amount of management overhead when building the running-config and would put people much closer to running into platform limitations because of the processing overhead.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2023 04:55:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-cant-a-url-be-used-directly-in-a-policy/m-p/563439#M114101</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-10-28T04:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why cant a URL be used directly in a policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-cant-a-url-be-used-directly-in-a-policy/m-p/563490#M114109</link>
      <description>&lt;P&gt;That makes sense, thank you very much!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 07:25:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-cant-a-url-be-used-directly-in-a-policy/m-p/563490#M114109</guid>
      <dc:creator>ABurger</dc:creator>
      <dc:date>2023-10-30T07:25:57Z</dc:date>
    </item>
  </channel>
</rss>

