<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help whitelisting a URL that routes through Cloudfront in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-whitelisting-a-url-that-routes-through-cloudfront/m-p/584371#M116730</link>
    <description>&lt;P data-unlink="true"&gt;Hi all, I am having trouble whitelisting a site and wanted to see what I can do about it.&amp;nbsp; The website I am whitelisting is&amp;nbsp;https://www.pahealthwellness.com/login.html.&amp;nbsp; When you make some selections on the page, it redirects to&amp;nbsp;https://sso.entrykeyid.com&amp;nbsp;.&amp;nbsp;I have a rule set to allow both those URL's with wildcards, but the bigger problem is that the traffic is hitting cloudfront and getting blocked based on that.&amp;nbsp; I dont want to whitelist all of cloudfront, but I cant figure out a way around this.&amp;nbsp; I can give more detail if needed, I just want to see if I am missing something basic here.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2024 20:23:35 GMT</pubDate>
    <dc:creator>BenOesterling</dc:creator>
    <dc:date>2024-04-19T20:23:35Z</dc:date>
    <item>
      <title>Help whitelisting a URL that routes through Cloudfront</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-whitelisting-a-url-that-routes-through-cloudfront/m-p/584371#M116730</link>
      <description>&lt;P data-unlink="true"&gt;Hi all, I am having trouble whitelisting a site and wanted to see what I can do about it.&amp;nbsp; The website I am whitelisting is&amp;nbsp;https://www.pahealthwellness.com/login.html.&amp;nbsp; When you make some selections on the page, it redirects to&amp;nbsp;https://sso.entrykeyid.com&amp;nbsp;.&amp;nbsp;I have a rule set to allow both those URL's with wildcards, but the bigger problem is that the traffic is hitting cloudfront and getting blocked based on that.&amp;nbsp; I dont want to whitelist all of cloudfront, but I cant figure out a way around this.&amp;nbsp; I can give more detail if needed, I just want to see if I am missing something basic here.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 20:23:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-whitelisting-a-url-that-routes-through-cloudfront/m-p/584371#M116730</guid>
      <dc:creator>BenOesterling</dc:creator>
      <dc:date>2024-04-19T20:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Help whitelisting a URL that routes through Cloudfront</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-whitelisting-a-url-that-routes-through-cloudfront/m-p/593533#M118132</link>
      <description>&lt;P&gt;I have a similar problem and I can't even get things to work after whitelisting *.cloudfront.net.&amp;nbsp; It's as if the laptop's DNS is resolving to an IP address different than the Palo Alto.&amp;nbsp; I have the Minimum FQDN refresh time set to zero in Device &amp;gt; Setup &amp;gt; Services but it still won't match the policy.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 16:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-whitelisting-a-url-that-routes-through-cloudfront/m-p/593533#M118132</guid>
      <dc:creator>EricHaug</dc:creator>
      <dc:date>2024-07-30T16:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help whitelisting a URL that routes through Cloudfront</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-whitelisting-a-url-that-routes-through-cloudfront/m-p/593569#M118135</link>
      <description>&lt;P&gt;It sounds (and after a quick check of pahealthwellness.com confirmed) that website is using fast-flux DNS. The DNS resolution is constantly changing over a range of IPs, so the firewall and client DNS responses will diverge, and hence the firewall doesn't know the IP the client browser is currently connecting to is actually the same as the FQDN in the firewall. There are really only 2 options if you want to whitelist this server and block other traffic. See my previous thread here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/panorama-discussions/frequently-changing-ip-for-a-fqdn/td-p/547597" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/panorama-discussions/frequently-changing-ip-for-a-fqdn/td-p/547597&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/cyberpedia/what-is-a-fast-flux-network" target="_blank" rel="noopener"&gt;https://www.paloaltonetworks.com/cyberpedia/what-is-a-fast-flux-network&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: The PA minimum FQDN refresh time will never drop below 30sec (regardless of the config setting) as that is hardcoded to prevent the firewall from thrashing on invalid/extremely short TTL FQDNs.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 21:10:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-whitelisting-a-url-that-routes-through-cloudfront/m-p/593569#M118135</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-07-30T21:10:07Z</dc:date>
    </item>
  </channel>
</rss>

