<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Conditional URL Blocking in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/conditional-url-blocking/m-p/27250#M19875</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey guys...so I have a request&amp;nbsp; - Users in my company who are not up to speed on corporate training will be added to the "corp\DelinquentUsers" AD group.&amp;nbsp; I need to make sure that these guys are only allowed to go to 5 websites while they are part of this group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently HTTP access is anything unless its matched in our URL blocking profile (Gambling, drugs, pr0n, religion, etc).&amp;nbsp; If you did NOT match the Delinquent Users AD group, then you would fall through to this rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im a little unclear on how to set up the URL filtering profile.&amp;nbsp; Can I just put a * in the blocked sites dialog and then the 5 sites we allow in the allowed sites?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Jul 2015 23:12:37 GMT</pubDate>
    <dc:creator>blaketraister</dc:creator>
    <dc:date>2015-07-20T23:12:37Z</dc:date>
    <item>
      <title>Conditional URL Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/conditional-url-blocking/m-p/27250#M19875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey guys...so I have a request&amp;nbsp; - Users in my company who are not up to speed on corporate training will be added to the "corp\DelinquentUsers" AD group.&amp;nbsp; I need to make sure that these guys are only allowed to go to 5 websites while they are part of this group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently HTTP access is anything unless its matched in our URL blocking profile (Gambling, drugs, pr0n, religion, etc).&amp;nbsp; If you did NOT match the Delinquent Users AD group, then you would fall through to this rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im a little unclear on how to set up the URL filtering profile.&amp;nbsp; Can I just put a * in the blocked sites dialog and then the 5 sites we allow in the allowed sites?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jul 2015 23:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/conditional-url-blocking/m-p/27250#M19875</guid>
      <dc:creator>blaketraister</dc:creator>
      <dc:date>2015-07-20T23:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional URL Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/conditional-url-blocking/m-p/27251#M19876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Putting an "*" in the BLOCK-list will not help you to allow those 5 websites.&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;The order of precedence taken:&lt;/P&gt;&lt;OL start="1" style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;LI&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Block list&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Allow list&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;custom categories &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;pre-defined categories&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Hence,i would request you to configure a new URL filtering profile for "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;corp\DelinquentUsers" AD group as mentioned below:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-style: inherit; font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-style: inherit; font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: inherit;"&gt;&lt;IMG alt="URL-filtering.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20373_URL-filtering.JPG" style="height: 326px; width: 620px;" /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Add this profile in your security policy for user group &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;corp\DelinquentUsers.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;HULK&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jul 2015 23:31:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/conditional-url-blocking/m-p/27251#M19876</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-07-20T23:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional URL Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/conditional-url-blocking/m-p/27252#M19877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is actually really simple:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Create a "Custom URL Category" called "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;DelinquentUsersAllow" or whatever else you wish to name it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;2.&amp;nbsp; Add the 5 URLs to this category&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;3.&amp;nbsp; Create a new URL Profile called "DelinquentUsersAllow" or whatever else you wish to name it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;4.&amp;nbsp; Set all URL categories in this new URL profile to "block" except for this new category being set to "alert"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;5.&amp;nbsp; Create a new rule in security policy which uses the AD group you wish as the source user, and also using this new URL profile.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jul 2015 18:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/conditional-url-blocking/m-p/27252#M19877</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-07-22T18:01:58Z</dc:date>
    </item>
  </channel>
</rss>

