<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic &amp;quot;Allow&amp;quot; Lists possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23478#M17124</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm migrating from regionalized TMG environment, to a distributed Palo Alto design at a great number of sites. One of the banes of our TMG existence is maintaining a list of allowed internet sites that anyone on the network can get to VIA a trust to untrust policy (Even those non-domain devices).&amp;nbsp; Things like HR sites, retirement, health care, etc.&amp;nbsp; This list is long, changes often, and must be changed on many firewalls.&amp;nbsp; We are looking for something a little more automated.&amp;nbsp; We are running 5.10 code, and will NOT have Panorama deployed until well into 2015.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL filtering is great.&amp;nbsp; Specifically, the ability to use wild cards in the URL's, and to chose weather to allow or deny traffic in policy.&amp;nbsp; However, modifications are tedious at best, and every firewall must be touched.&amp;nbsp; (Well over 150 right now!)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Dynamic Block Lists are nearly perfect for this task, if only they could be "Dynamic Lists" and &lt;EM&gt;we could chose&lt;/EM&gt; to block or allow.&amp;nbsp; The disadvantage here is that EBL's are IP addresses, and not URL's.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to maintain a list of URLs in a text or XML file on a server, to be referenced by an "Allow" policy, on all of the firewalls on some interval?&amp;nbsp; In other words, Dynamic Block List behavior, with URL filter functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can it be done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Sep 2014 18:40:48 GMT</pubDate>
    <dc:creator>aklugherz</dc:creator>
    <dc:date>2014-09-22T18:40:48Z</dc:date>
    <item>
      <title>Dynamic "Allow" Lists possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23478#M17124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm migrating from regionalized TMG environment, to a distributed Palo Alto design at a great number of sites. One of the banes of our TMG existence is maintaining a list of allowed internet sites that anyone on the network can get to VIA a trust to untrust policy (Even those non-domain devices).&amp;nbsp; Things like HR sites, retirement, health care, etc.&amp;nbsp; This list is long, changes often, and must be changed on many firewalls.&amp;nbsp; We are looking for something a little more automated.&amp;nbsp; We are running 5.10 code, and will NOT have Panorama deployed until well into 2015.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL filtering is great.&amp;nbsp; Specifically, the ability to use wild cards in the URL's, and to chose weather to allow or deny traffic in policy.&amp;nbsp; However, modifications are tedious at best, and every firewall must be touched.&amp;nbsp; (Well over 150 right now!)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Dynamic Block Lists are nearly perfect for this task, if only they could be "Dynamic Lists" and &lt;EM&gt;we could chose&lt;/EM&gt; to block or allow.&amp;nbsp; The disadvantage here is that EBL's are IP addresses, and not URL's.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to maintain a list of URLs in a text or XML file on a server, to be referenced by an "Allow" policy, on all of the firewalls on some interval?&amp;nbsp; In other words, Dynamic Block List behavior, with URL filter functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can it be done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2014 18:40:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23478#M17124</guid>
      <dc:creator>aklugherz</dc:creator>
      <dc:date>2014-09-22T18:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic "Allow" Lists possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23479#M17125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aklugherz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dynamic Block list allow only subnet/IPs in it. Rest all is illegal and it just ignore it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didnt find any existing Feature Request for the same. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik SHah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2014 18:50:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23479#M17125</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-22T18:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic "Allow" Lists possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23480#M17126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aklugherz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont see any way to add lots of URLs in text file which firewall can use. I would suggest to contact your Sales Engineer, he might have better insight to this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2014 19:30:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23480#M17126</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-22T19:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic "Allow" Lists possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23481#M17127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1420" data-externalid="" data-presence="null" data-userid="29734" data-username="aklugherz" href="https://live.paloaltonetworks.com/people/aklugherz" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;aklugherz&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Please find below few&lt;/SPAN&gt; documents regarding EBL, for your reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5850"&gt;Configuring Dynamic Block List (EBL) on a Palo Alto Networks Device&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4724"&gt;Working with External Block List (EBL) Formats and Limitations&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2014 19:42:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23481#M17127</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-22T19:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic "Allow" Lists possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23482#M17128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use dynamic block lists to block websites.&amp;nbsp; It's fantastic, in that we only have to maintain a single file with bad sites on a server somewhere, and the firewalls just go get it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm looking for now is the exact &lt;EM&gt;opposite&lt;/EM&gt; effect:&amp;nbsp; A file hosted on a server, that lists URL's that are &lt;STRONG&gt;allowed&lt;/STRONG&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2014 19:48:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23482#M17128</guid>
      <dc:creator>aklugherz</dc:creator>
      <dc:date>2014-09-22T19:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic "Allow" Lists possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23483#M17129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We do have the option to add sites to a whitelist in the URL profile, but it wouldn't be exactly like the External Block List you mentioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Oct 2014 17:56:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23483#M17129</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2014-10-03T17:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic "Allow" Lists possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23484#M17130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1420" data-externalid="" data-presence="null" data-userid="29734" data-username="aklugherz" href="https://live.paloaltonetworks.com/people/aklugherz" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;aklugherz&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the dynamic allow list is not supported at the moment with PAN firewall. Do not see any existing feature requests as well. As suggested previously, your best bet would be to contact your SE who can file a request on your behalf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Oct 2014 20:45:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-quot-allow-quot-lists-possible/m-p/23484#M17130</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-03T20:45:13Z</dc:date>
    </item>
  </channel>
</rss>

