<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filter - Block one and log the rest in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24498#M17859</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can try to create an object using an fqdn and try to apply in in a policy, but it looks like you may need to invest in url filtering.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Nov 2012 23:58:12 GMT</pubDate>
    <dc:creator>nayubi</dc:creator>
    <dc:date>2012-11-30T23:58:12Z</dc:date>
    <item>
      <title>URL Filter - Block one and log the rest</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24497#M17858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On a PAN with no BrightCloud license, you can still use the URL filtering "Block" and "Allow" lists. Right now I use that feature to have a "log-all" URL filtering policy where I have "*" in the block list and an action of "alert." But now I have one (or it could be a short list) of URLs that I want to really block, i.e. an action of "block." However, if I change my block list to block that one URL with a "block" action, I lose all of my logging of other URLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to block my URL while still logging everything else that I'm not seeing? Kind of seems like something that should be easy (block some URLs while still retaining the ability to alert others), but I don't see how I can do it reliably.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 22:49:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24497#M17858</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2012-11-30T22:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filter - Block one and log the rest</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24498#M17859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can try to create an object using an fqdn and try to apply in in a policy, but it looks like you may need to invest in url filtering.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 23:58:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24498#M17859</guid>
      <dc:creator>nayubi</dc:creator>
      <dc:date>2012-11-30T23:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filter - Block one and log the rest</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24499#M17860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the absence of a URL filtering license, you should also be able to create a custom category.&amp;nbsp; So if you really need to, create a custom category with the URL you'd like to block, and then continue using the block list to alert on the rest.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Dec 2012 01:14:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24499#M17860</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2012-12-01T01:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filter - Block one and log the rest</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24500#M17861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. Wasn't sure if custom URLs worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what I did was create a custom URL category for the sites I want to block:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# show profiles custom-url-category &lt;/P&gt;&lt;P&gt;custom-url-category {&lt;/P&gt;&lt;P&gt;&amp;nbsp; wpad {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; list [ wpad.am.example.com wpad.example.com];&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I create a policy rule that uses that URL category,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# show rulebase security rules "Block WPAD" &lt;/P&gt;&lt;P&gt;"Block WPAD" {&lt;/P&gt;&lt;P&gt;&amp;nbsp; source any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; service application-default;&lt;/P&gt;&lt;P&gt;&amp;nbsp; application web-browsing;&lt;/P&gt;&lt;P&gt;&amp;nbsp; action allow;&lt;/P&gt;&lt;P&gt;&amp;nbsp; source-user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; option {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; disable-server-response-inspection no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; negate-source no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; negate-destination no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; disabled no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; log-end yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; from dc;&lt;/P&gt;&lt;P&gt;&amp;nbsp; to internal;&lt;/P&gt;&lt;P&gt;&amp;nbsp; log-setting Panorama-ALL;&lt;/P&gt;&lt;P&gt;&amp;nbsp; hip-profiles any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; log-start no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; category wpad;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't be mislead by the name. The action us currently "allow" while I make sure the rule does not catch traffic inadvertently. And I am a little puzzled by the results. If I do hit a URL that matches the URL category, I get the expected entry in my logs. However, I see a lot of logs,&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;App&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;From&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;Src Port&amp;nbsp;&amp;nbsp; Source&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Rule&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;Action&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;To&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;Dst Port&amp;nbsp;&amp;nbsp; Destination&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;Src User&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;Dst User&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;===============================================================================&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2012/12/03 10:13:41 incomplete&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;dc&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;63803 &lt;/TD&gt;&lt;TD&gt;172.31.152.165&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Block WPAD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;allow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;internal&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;80&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;192.168.208.131&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2012/12/03 10:13:37 incomplete&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;dc&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;50620 &lt;/TD&gt;&lt;TD&gt;10.10.10.77&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Block WPAD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;allow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;internal&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;80&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;192.168.228.45&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2012/12/03 10:13:36 incomplete&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;dc&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;63802 &lt;/TD&gt;&lt;TD&gt;172.31.152.165&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Block WPAD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;allow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;internal&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;80&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;192.168.208.131&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even though they are "incomplete," I believe the connections are in fact working. Not sure what these logs mean. I believe they are successful HTTP connections, but the URL does not match. I would expect not to see any log entry at all if that were the case. Is this expected behavior?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Dec 2012 18:18:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filter-block-one-and-log-the-rest/m-p/24500#M17861</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2012-12-03T18:18:57Z</dc:date>
    </item>
  </channel>
</rss>

