<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/596906#M118739</link>
    <description>&lt;P&gt;Does Palo alto lookup source and destination zones and IP addresses before matching a URL category?we have a scenario in which we have created a Custom URL category and applied it in one security policy but Palo alto is matching that Custom URL category to many Security Policies regardless of the Source and Destination zones and IP addresses.Is this an expected behavior?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2024 01:37:08 GMT</pubDate>
    <dc:creator>UmerSalahuddin</dc:creator>
    <dc:date>2024-09-05T01:37:08Z</dc:date>
    <item>
      <title>What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2642#M1974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, Guys, I have one question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First below is the packet flow from "Packet Flow.pdf" document. According to this document ...&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8746_1.jpg" style="font-size: 10pt; line-height: 1.5em; width: 620px; height: 437px;" /&gt;&lt;/P&gt;&lt;P&gt;In the red square, before PA make session table, it checks packet's ip and port (like the legacy L4 firewall), and then after the session created, it check Content, APP-ID.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So I made this rule(URL Block).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8765_2.jpg" style="width: 620px; height: 331px;" /&gt;&lt;/P&gt;&lt;P&gt;According to packet flow.pdf, 'URL Block' rule should check packet's ip and port first and then should block those packet. &lt;STRONG&gt;&amp;gt;&amp;gt; Am I right?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;That means that the packet would never go Contents-ID, and APP-ID process. And URL filtering happens in Content ID process.&lt;/P&gt;&lt;P&gt;According to the document ,the session should never be created.&lt;/P&gt;&lt;P&gt;But in my lab test, it worked fine as the rule made (It worked like as if I used URL filtering profile.&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;If I use URL filtering profile, the action should be 'allow' in security rule, and 'block that category' in url filtering profile.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just wondering, then what's the difference between in Security policy and Security Profile URL filtering.&lt;/P&gt;&lt;P&gt;And I want to hear your opinion. It would be very appreciated if you point out what's my mis-understading.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 01:18:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2642#M1974</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-10-02T01:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2643#M1975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello JTR,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you use a URL category in a security rule you are applying various security profiles (URL, Spyware, FIle Blocking, Vulnerability, Antivirus and Data) against websites that are categorized based on the categories that you have selected in the security policy.&amp;nbsp; An example of this might be to apply a stronger set of profiles when visiting social media sites.&amp;nbsp;&amp;nbsp; In some ways it is just a matter of what approach you want to take.&amp;nbsp;&amp;nbsp; The other approach may be to have stricter security profiles applied to all traffic originating from certain parts of your network regardless of the type of website (category).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this adds some clarity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Oct 2013 02:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2643#M1975</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-10-05T02:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2644#M1976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really Thanks Phil.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually I'm very confused. Do you mean that I shouldn't use URL category in security policy just for blocking some specific URL?&lt;/P&gt;&lt;P&gt;Let say I want to block 'www.google.co.kr' URL with custom category in security policy. Are you saying that this is not a good example?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="googleblock.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8922_googleblock.jpg" style="width: 620px; height: 323px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It worked just like I make some url profile with google site blocked in black list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 02:46:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2644#M1976</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-10-07T02:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2645#M1977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should better use custom url list for that.Make your list, choose block in url filtering profile for that custom list, make this profile to be used in security rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also a deny rule will never use security profile.so category3 rule's profiles will not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 08:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2645#M1977</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-07T08:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2646#M1978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;url category&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;used in policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only matches pre-defined or custom category&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action is related to policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logged as traffic log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;URL filtering&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apllied to allowed security policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can match pre-defined,custom category and &lt;/P&gt;&lt;P&gt;also allow/block list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action can be configured individual by URLS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logged in URL filtering log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 08:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2646#M1978</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-07T08:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2647#M1979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's related application based on HTTP and SSL protocol only and used in policy with action of security policy. It's a very useful feature to control URLs on HTTP and SSL and Administrator can be understanding definitely with watching only security policy (not to check URL filter profile in another window) when he try to control the URLs to be allowed or denied.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I believe that most of Admins requested to control URLs definitely in security policy so PANW created that URL control in policy. I've liked that feature for creating security policy with controlling few URLs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; Have a good Korean Holyday called HanGeulNal.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Roh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 05:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2647#M1979</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-08T05:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2648#M1980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI &lt;/P&gt;&lt;P style="margin-top: 4.32pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;here URL Filtering feature can be used by &lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;placing categories directly in &lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;policies or attaching a URL &lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;Filtering profile &lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;to a security rule. URL filtering only affects HTTP and HTTPS traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 4.32pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;The URL Category field can be used as a match condition for security, QoS, decryption, and Captive Portal policies. Both pre-defined and custom categories can be matched when using the URL category field. The URL category itself does not have an associated action – traffic behavior is controlled by the policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 4.32pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;The URL Filtering security profile provides granular control for traffic allowed by a security policy. As with other profiles, the URL filtering profile is only applied if the associated policy allows traffic. The profile can match URL categories, as well as individual URLs. Each category can be assigned a different action for more focused management. For example, a security policy could be created to allow all web browsing but have a policy which blocks all access to file sharing websites and logs all access to social networks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 4.32pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 4.32pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: Arial; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 08:38:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2648#M1980</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-10-08T08:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2649#M1981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really thank you for your kind reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one more question about flow logic. Below red square area.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="flow.jpg" class="jive-image jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/9024_flow.jpg" /&gt;&lt;/P&gt;&lt;P&gt;Does this red square means....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. PA ignore application category in security policy by setting the app category value from 'something' to 'any'.&lt;/P&gt;&lt;P&gt;In the below picture, PA set rule1's application category from 'web-browsing' to 'any', and then do security policy lookup and find out rule2. &lt;/P&gt;&lt;P&gt;After PA find out rule2 , PA makes session table , then do the application-ID, then block the 'web-browsing' by using rule1.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="rule1.jpg" class="jive-image" height="73" src="https://live.paloaltonetworks.com/legacyfs/online/9025_rule1.jpg" style="width: 1028.6363636363637px; height: 73px;" width="1029" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. PA checks whether there's any security rule which has 'any' value in app category.&lt;/P&gt;&lt;P&gt;In below picture, PA do security rule lookup which has 'any' value in its Application category and find rule2, then setup the session table,and do the App-ID, finally block 'web-browsing'.&lt;/P&gt;&lt;P&gt; &lt;IMG alt="rule1.jpg" class="jive-image jiveImage" height="73" src="https://live.paloaltonetworks.com/legacyfs/online/9025_rule1.jpg" width="1029" /&gt;&lt;/P&gt;&lt;P&gt;What does the PA exactly do in the red square process? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 08:39:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/2649#M1981</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-10-10T08:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/596906#M118739</link>
      <description>&lt;P&gt;Does Palo alto lookup source and destination zones and IP addresses before matching a URL category?we have a scenario in which we have created a Custom URL category and applied it in one security policy but Palo alto is matching that Custom URL category to many Security Policies regardless of the Source and Destination zones and IP addresses.Is this an expected behavior?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 01:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/596906#M118739</guid>
      <dc:creator>UmerSalahuddin</dc:creator>
      <dc:date>2024-09-05T01:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/597039#M118761</link>
      <description>&lt;P&gt;Traffic will match the first Security Policy that fits the available information at the time of the initial connection (which is usually only the source/destination and possibly IP protocol), and will be re-evaluated to match later Security Policies if new information from the connection no longer matches the existing policy. If you have a Security Policy based on IP/destination zone, then all traffic to that destination will match, even if there is a more specific Application/URL policy later on. If you have a Security Policy with only custom URL Category as a matching filter, then the PaloAlto will match all potential traffic to that Security Policy until the URL can be determined not to match (as a HTTP URL request doesn't come until multiple packets into a TCP session). The same applies for Application/Service matching. So generally you want to make your initial Security Policies as specific as possible, and have more general rules afterward to catch non-specific traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if you have Security Policy that has filters for:&lt;/P&gt;
&lt;P&gt;1) Destination IP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; --&amp;gt; matches all traffic to that destination, regardless of any other factor&lt;/P&gt;
&lt;P&gt;2) URL Category:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; --&amp;gt; matches all traffic (not necessarily port 80/443) until the URL can be determined not to match&lt;/P&gt;
&lt;P&gt;3) Application/Service, URL Category&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; --&amp;gt; matches all corresponding Application/Service traffic until URL can be determined not to match&lt;/P&gt;
&lt;P&gt;4) Destination IP/range,&amp;nbsp;Application/Service, URL Category&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; --&amp;gt; matches all corresponding destination IP and Application/Service specific traffic until URL can be determined not to match&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 21:59:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-custom-url-filtering-in-security/m-p/597039#M118761</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-09-05T21:59:29Z</dc:date>
    </item>
  </channel>
</rss>

