<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain/IP categorisation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/domain-ip-categorisation/m-p/1238797#M125220</link>
    <description>&lt;P&gt;you can use an API to query the firewall for a url category:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;curl -k "https://&amp;lt;firewall IP&amp;gt;/api/?key="&amp;lt;APIkey&amp;gt;"&amp;amp;type=op&amp;amp;cmd=&amp;lt;test&amp;gt;&amp;lt;url&amp;gt;yoursitehere&amp;lt;/url&amp;gt;&amp;lt;/test&amp;gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Sep 2025 14:40:40 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2025-09-25T14:40:40Z</dc:date>
    <item>
      <title>Domain/IP categorisation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/domain-ip-categorisation/m-p/1238563#M125203</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;I am using a&amp;nbsp;&lt;SPAN&gt;PA-5250 with PAN-OS&amp;nbsp;11.1.6-h10. Our environment makes use of the automated correlation engine correlated events. So for example we get alerts like this one:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="x-window-ml"&gt;
&lt;DIV class="x-window-mr"&gt;
&lt;DIV id="ext-gen6754" class="x-window-mc"&gt;
&lt;DIV id="ext-gen6751" class="x-window-body"&gt;
&lt;DIV id="MatchesDetailedLogPanel" class=" x-panel darkblue-container"&gt;
&lt;DIV id="ext-gen6768" class="x-panel-bwrap"&gt;
&lt;DIV id="ext-gen6769" class="x-panel-body x-panel-body-noheader"&gt;
&lt;DIV id="ext-comp-3664" class=" x-tab-panel"&gt;
&lt;DIV id="ext-gen6772" class="x-tab-panel-bwrap"&gt;
&lt;DIV id="ext-gen6773" class="x-tab-panel-body x-tab-panel-body-top"&gt;
&lt;DIV id="ext-comp-3665" class=" x-no-padding"&gt;
&lt;DIV id="ext-comp-3666"&gt;
&lt;DIV id="ext-comp-3677" class=" x-panel x-portal x-panel-noborder"&gt;
&lt;DIV id="ext-gen6806" class="x-panel-bwrap"&gt;
&lt;DIV id="ext-gen6807" class="x-panel-body x-panel-body-noheader x-panel-body-noborder x-column-layout-ct"&gt;
&lt;DIV id="ext-gen6809" class="x-column-inner"&gt;
&lt;DIV id="ext-comp-3678" class=" x-portal-column x-first-column x-last-column x-column"&gt;
&lt;DIV id="ext-comp-3672" class=" x-panel  x-portlet load-mask-displayer grey x-panel-noborder x-form-label-left"&gt;
&lt;DIV id="ext-gen6820" class="x-panel-bwrap"&gt;
&lt;DIV class="x-panel-ml"&gt;
&lt;DIV class="x-panel-mr"&gt;
&lt;DIV id="ext-gen6822" class="x-panel-mc"&gt;&lt;FORM id="ext-gen6746" class="x-panel-body x-panel-body-noborder x-form" method="POST"&gt;
&lt;DIV id="ext-comp-3673" class=" x-column-layout-ct"&gt;
&lt;DIV id="ext-gen6836" class="x-column-inner"&gt;
&lt;DIV id="ext-comp-3674" class=" x-form-label-left x-column"&gt;
&lt;DIV id="ext-comp-3675" class=" x-panel undefined pan_widget x-list-panel"&gt;
&lt;DIV id="ext-gen6839" class="x-panel-bwrap"&gt;
&lt;DIV id="ext-gen6840" class="x-panel-body x-panel-body-noheader"&gt;
&lt;DIV id="ext-comp-3676" class="x-list-wrap undefined pan_widget"&gt;
&lt;DIV class="x-list-body"&gt;
&lt;DIV id="ext-gen6842" class="x-list-body-inner"&gt;
&lt;DL&gt;
&lt;DT&gt;&lt;EM class="x-grid-selectable"&gt;Host repeatedly visited uncategorized domain (6 times), and performed EXE downloads from these domains.&lt;/EM&gt;&lt;/DT&gt;
&lt;/DL&gt;
&lt;DIV class="x-clear"&gt;The hosts that are responsible for generating these alerts are legitimate in our case.&lt;BR /&gt;So a fix would be to categorise the matching domain with the URL filtering tool&amp;nbsp;&lt;A href="https://urlfiltering.paloaltonetworks.com/" target="_blank"&gt;Palo Alto Networks URL filtering - Test A Site&lt;/A&gt;. I was wondering if I could categorise the hosts locally on the Palo Alto Firewall instead of using the URL filtering tool.&lt;BR /&gt;&lt;BR /&gt;The hosts I would like to categorise are public IP adresses instead of url's/ dns names since the IP adresses that generate these alerts do not have any DNS record pointing to them. And since there are quit a bit of IP adresses I would like to categorise these locally on the firewall itself. I have already tried making a custom URL Category and adding the IP adresses here. But this seems to have no effect. The correlated events are still coming in.&lt;BR /&gt;&lt;BR /&gt;Anyone here knows a way to achieve this if this is even possible?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks in advance!&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="ext-gen6837" class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/FORM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="ext-gen6821" class="x-panel-bl x-panel-nofooter"&gt;
&lt;DIV class="x-panel-br"&gt;
&lt;DIV class="x-panel-bc"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="ext-gen6810" class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="ext-gen6753" class="x-window-bl"&gt;
&lt;DIV class="x-window-br"&gt;
&lt;DIV class="x-window-bc"&gt;
&lt;DIV id="ext-gen6752" class="x-window-footer x-panel-btns"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 09:46:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/domain-ip-categorisation/m-p/1238563#M125203</guid>
      <dc:creator>L.Cartooms</dc:creator>
      <dc:date>2025-09-23T09:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Domain/IP categorisation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/domain-ip-categorisation/m-p/1238797#M125220</link>
      <description>&lt;P&gt;you can use an API to query the firewall for a url category:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;curl -k "https://&amp;lt;firewall IP&amp;gt;/api/?key="&amp;lt;APIkey&amp;gt;"&amp;amp;type=op&amp;amp;cmd=&amp;lt;test&amp;gt;&amp;lt;url&amp;gt;yoursitehere&amp;lt;/url&amp;gt;&amp;lt;/test&amp;gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 14:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/domain-ip-categorisation/m-p/1238797#M125220</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-09-25T14:40:40Z</dc:date>
    </item>
  </channel>
</rss>

