<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to do URL Whitelists? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18781#M13682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...You should set the security rule for that address group with service=tcp/80, action=allow and the selected URL profile.&amp;nbsp; In the selected URL profile, add the permitted URLs to the allow-list, allow content-delivery-network category, and block all other URL categories .&amp;nbsp; Maybe you missed setting all other categories to block.&amp;nbsp; You may need to check the URL filtering log and unblock other URLs as appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Aug 2013 17:36:50 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2013-08-26T17:36:50Z</dc:date>
    <item>
      <title>How to do URL Whitelists?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18780#M13681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to figure out how to do Whitelists for a list of URLs and I am not having much luck. &lt;/P&gt;&lt;P&gt;By default all outgoing is allowed on everything internal. &lt;/P&gt;&lt;P&gt;I have a group of addresses that should only be allowed to view certain websites with wildcards. &lt;/P&gt;&lt;P&gt;I created a profile that is set to that address group for source, ANY for everything else, and a URL Profile with the list of URLs in the whitelist. When that policy is set to Deny it blocks all traffic and if it is set to Allow it allows all traffic. &lt;/P&gt;&lt;P&gt;An example URL I am using is www.google.com/*&lt;/P&gt;&lt;P&gt;I have this policy above our Allow all rule. If I I put it beneath the allow rule it does not apply. We do have the url filtering license also. &lt;/P&gt;&lt;P&gt;What exactly am I doing wrong here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Aug 2013 17:21:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18780#M13681</guid>
      <dc:creator>jeffm</dc:creator>
      <dc:date>2013-08-26T17:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to do URL Whitelists?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18781#M13682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...You should set the security rule for that address group with service=tcp/80, action=allow and the selected URL profile.&amp;nbsp; In the selected URL profile, add the permitted URLs to the allow-list, allow content-delivery-network category, and block all other URL categories .&amp;nbsp; Maybe you missed setting all other categories to block.&amp;nbsp; You may need to check the URL filtering log and unblock other URLs as appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Aug 2013 17:36:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18781#M13682</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-08-26T17:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to do URL Whitelists?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18782#M13683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the help. I have it mostly working but one thing is still rather weird. &lt;/P&gt;&lt;P&gt;For each site I am having to do 4 white list entries. &lt;/P&gt;&lt;P&gt;For example one site is saemtests.org&lt;/P&gt;&lt;P&gt;If they don't put www&lt;/P&gt;&lt;P&gt;saemtests.org/*&lt;/P&gt;&lt;P&gt;saemtests.org/&lt;/P&gt;&lt;P&gt;If they put www&lt;/P&gt;&lt;P&gt;*.saemtests.org/*&lt;/P&gt;&lt;P&gt;*.saemtests.org/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this normal or is there a regular expression I should be using instead?&lt;/P&gt;&lt;P&gt;I tried doing *saemtests* however that was not valid. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 13:27:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18782#M13683</guid>
      <dc:creator>jeffm</dc:creator>
      <dc:date>2013-08-28T13:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to do URL Whitelists?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18783#M13684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When doing a whitelist, you should put for example:&lt;/P&gt;&lt;P&gt;saemtests.org&lt;/P&gt;&lt;P&gt;*.saemtests.org&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 14:10:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18783#M13684</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2013-08-28T14:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to do URL Whitelists?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18784#M13685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the help note.Did you read that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="1713857"&gt;For &lt;/A&gt;example, "www.paloaltonetworks.com” is different from "paloaltonetworks.com". If you want to block the entire domain, you should include both "*.paloaltonetworks.com" and "paloaltonetworks.com". &lt;/P&gt;&lt;P class="TB_TableBody"&gt;&lt;A name="1574073"&gt;Examples: &lt;/A&gt;&lt;/P&gt;&lt;P class="TB1_TableBullet_outer"&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" summary=""&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="TB1_TableBullet_inner"&gt;•&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="100%"&gt;&lt;P class="TB1_TableBullet_inner"&gt;&lt;A name="1479667"&gt;www.paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P class="TB1_TableBullet_outer"&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" summary=""&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="TB1_TableBullet_inner"&gt;•&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="100%"&gt;&lt;P class="TB1_TableBullet_inner"&gt;&lt;A name="1479668"&gt;198.133.219.25/en/US&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P class="TB_TableBody"&gt;&lt;A name="1479669"&gt;Block and allow lists support wildcard patterns. The following characters &lt;/A&gt;are considered separators: &lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; margin-bottom: 0.0pt; text-indent: 18pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479670"&gt;.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; margin-bottom: 0.0pt; text-indent: 18pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479671"&gt;/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; margin-bottom: 0.0pt; text-indent: 18pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479672"&gt;?&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; margin-bottom: 0.0pt; text-indent: 18pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479673"&gt;&amp;amp;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; margin-bottom: 0.0pt; text-indent: 18pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479674"&gt;=&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; margin-bottom: 0.0pt; text-indent: 18pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479675"&gt;;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; margin-bottom: 0.0pt; text-indent: 18pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479676"&gt;+&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody"&gt;&lt;A name="1479677"&gt;Every substring that is separated by the characters listed above is &lt;/A&gt;considered a token. A token can be any number of ASCII characters that does not contain any separator character or *. For example, the following patterns are valid:&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 8.5pt; font-style: italic; font-weight: normal; margin-bottom: 2.0pt; text-indent: 7.2pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 8.5pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479678"&gt;*.yahoo.com (Tokens are: "*", "yahoo" and "com")&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 8.5pt; font-style: italic; font-weight: normal; margin-bottom: 2.0pt; text-indent: 7.2pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 8.5pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479679"&gt;www.*.com (Tokens are: "www", "*" and "com")&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 8.5pt; font-style: italic; font-weight: normal; margin-bottom: 2.0pt; text-indent: 7.2pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 8.5pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479680"&gt;www.yahoo.com/search=* (Tokens are: "www", "yahoo", "com", "search", "*")&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="margin-top: 3.0pt;"&gt;&lt;A name="1479681"&gt;The following patterns are invalid because the character “*” is not the &lt;/A&gt;only character in the token.&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; text-indent: 7.2pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479682"&gt;ww*.yahoo.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 9.0pt; font-style: italic; font-weight: normal; text-indent: 7.2pt;"&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 9.0pt; font-style: italic; font-weight: normal;"&gt;&lt;A name="1479683"&gt;www.y*.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 14:15:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-do-url-whitelists/m-p/18784#M13685</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-28T14:15:40Z</dc:date>
    </item>
  </channel>
</rss>

