<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trying to block only certain websites using 3.1.6 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19553#M14285</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only thing you can do is looking at your URL Logs for supect "block-url" actions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many times a web page has links that points to other websites wich are probably blocked by your Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to make an exception for CNN and other sites I suggest you to insert something like that for all sites you want in the Allow List:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*.cnn.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example enablig Facebook only with Allow List would be tricky, because Facebook calls many different domain such as: fcbn.com etc.&lt;/P&gt;&lt;P&gt;So, you would need to have a list of all domain called...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;p.s Remember, your logs always say you the truth! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Aug 2011 15:48:25 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2011-08-22T15:48:25Z</dc:date>
    <item>
      <title>Trying to block only certain websites using 3.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19548#M14280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need some help. I am very new to using firewalls and am not scheduled to go to class for Palo Alto until the first week of September. In the mean time I am trying to block a group of users from accessing the internet other than about 10 sites. I have tried everything I know how to do and even stuff I am just trying to figure out to do and I get it to block all sites but not let the ones through I need it to let through. I would appreciate any help anyone can give.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 20:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19548#M14280</guid>
      <dc:creator>JeffTQT</dc:creator>
      <dc:date>2011-08-17T20:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to block only certain websites using 3.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19549#M14281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using active directory? or will you be blocking users by IP?&amp;nbsp; (this will come in handy later)&lt;/P&gt;&lt;P&gt;First, I would recommend upgrading to 3.1.9, since there are some bugs that I encountered in 3.1.6 and 3.1.8 with URL filtering. There are some guides on the support site that make the upgrade pretty painless.&lt;/P&gt;&lt;P&gt;Before you start writing the rules, go to Objects -&amp;gt; Security Profiles -&amp;gt; URL Filtering rules.&lt;/P&gt;&lt;P&gt;Create a new URL filtering profile.&lt;/P&gt;&lt;P&gt;After you give the url filtering profile a name and description, check the dynamic URL filtering box.&lt;/P&gt;&lt;P&gt;Near the bottomf of the window, you will a box called "allow List". Enter the 10 URL that you wish to allow.&lt;/P&gt;&lt;P&gt;Now, on the right you will see all the different categories. Go to the very top and find the option "Set for all categories". Under the column "action" set it to block. This means that all the websites in all the categories will be blocked by the PAN.&lt;/P&gt;&lt;P&gt;Then click ok.&lt;/P&gt;&lt;P&gt;You have a new URL filtering profile that blocks all categories but allows the 10 URL that you have in your whitelist.&lt;/P&gt;&lt;P&gt;All you have to do is add this URL Filtering profile to a rule. On the far right of the rule, you will see a column lableled "profile". Click on the word "none" and select the url filerting profile that you created.&lt;/P&gt;&lt;P&gt;Now go ahead and test.&lt;/P&gt;&lt;P&gt;One last personnal recommendation. It's usually better to write the most specific / constrictive rules ahead of the more general / less restrictive rules.&lt;/P&gt;&lt;P&gt;Make sure that your blocking rule is ahead of your general web browsing rule that you have set for the remaining users.&lt;/P&gt;&lt;P&gt;Also, are you getting you training at Trace3? I'm sending one of my SE there too for training. Those are good folks there. Ask lots of questions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 22:57:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19549#M14281</guid>
      <dc:creator>camkim_MDEA</dc:creator>
      <dc:date>2011-08-17T22:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to block only certain websites using 3.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19550#M14282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate the help. I will try this now but I have another question to go with it. I am blocking using a special AD group just for this rule. As far as upgrading to 3.1.9 I am going to training on the 4.0 in 2 weeks and then we will be upgrading to that so moving to 3.1.9 at this point would be a waste. On the rule I am making do I make it a block or allow rule? I am assuming block but I just want to make sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I am going to Trace3 for my training. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 13:50:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19550#M14282</guid>
      <dc:creator>JeffTQT</dc:creator>
      <dc:date>2011-08-22T13:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to block only certain websites using 3.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19551#M14283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;in every rule you want associate a Security Profile to (aka Content Inspection - AV, AS, URL, DLP, File Blocking) you MUST use the ALLOW action. If you put DENY traffic will not be inspected by Content-ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 14:13:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19551#M14283</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-08-22T14:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to block only certain websites using 3.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19552#M14284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the response. I got it working thanks to the help from you guys. I had done everything right originally other than the part about checking the dynamic URL box. What exactly does that do for it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have it working but there is a problem with the news sites. CNN, MSNBC, MSN, and Fox news sites all come through but only parts of the site. Pictures do not come through and the site in general is just not right. What could be causing this and is there anything I can do to get it corrected?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 14:58:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19552#M14284</guid>
      <dc:creator>JeffTQT</dc:creator>
      <dc:date>2011-08-22T14:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to block only certain websites using 3.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19553#M14285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only thing you can do is looking at your URL Logs for supect "block-url" actions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many times a web page has links that points to other websites wich are probably blocked by your Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to make an exception for CNN and other sites I suggest you to insert something like that for all sites you want in the Allow List:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*.cnn.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example enablig Facebook only with Allow List would be tricky, because Facebook calls many different domain such as: fcbn.com etc.&lt;/P&gt;&lt;P&gt;So, you would need to have a list of all domain called...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;p.s Remember, your logs always say you the truth! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 15:48:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19553#M14285</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-08-22T15:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to block only certain websites using 3.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19554#M14286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The option for Dynamic URL filtering allows the device to query the BrightCloud server when a URL is not found on-device.&amp;nbsp; Essentially, what this does is allows you to have access to the master database and not be limited to the entries on your device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In regards to certain parts of cnn.com, msnbc.com, msn.com, etc getting blocked, please check your URL filtering logs for a better explanation.&amp;nbsp; As mentioned in a previous post, sites often pull content from other sites which are often categorized as web-advertisements, content-delivery, etc, which depending on your URL filtering profile, could be blocked.&amp;nbsp; Check your URL filtering logs to see what these category these were and then check your URL filtering profile to confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 23:29:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-block-only-certain-websites-using-3-1-6/m-p/19554#M14286</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2011-08-22T23:29:34Z</dc:date>
    </item>
  </channel>
</rss>

