<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Allow List filters are not functioning as documented. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31517#M23056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you need allowing a domain with its subdomain you must allow them &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;domain.*&lt;/P&gt;&lt;P&gt;*.domain.*&lt;/P&gt;&lt;P&gt;*.*domain.*&lt;/P&gt;&lt;P&gt;*.*.*domain.*&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works for web-browsing, if the traffic is ssl you need to terminate it (decryptin) in order to gain full compatibility. If not only the domain.* is visible.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;In case of known application (as dropbox)&amp;nbsp; I suggest you not to use Url, use application identification, always go beyond Url Profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Jun 2013 15:02:25 GMT</pubDate>
    <dc:creator>NGS_SOC</dc:creator>
    <dc:date>2013-06-15T15:02:25Z</dc:date>
    <item>
      <title>URL Allow List filters are not functioning as documented.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31515#M23054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;URL filter is great when working with Categories, but when an exception is published in the allow list there are catches and exceptions.:smileyconfused:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We block-continue Streaming Media, which contains Youtube, which we want to allow users access to without a block.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I create an allow exception &lt;SPAN style="color: #3366ff;"&gt;*.youtube.com/*&lt;/SPAN&gt; and commit, open a new browser, clear the cache, and go to www,youtube.com to see that B&amp;amp;C is still in effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I added &lt;SPAN style="color: #3366ff;"&gt;www.youtube.com&lt;/SPAN&gt; and &lt;SPAN style="color: #3366ff;"&gt;youtube.com&lt;/SPAN&gt; in addition, and then it worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did the same thing for dropbox, but it uses HTTPS and the session would be dropped every time I went to www.dropbox.com - which in turn redirected me to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://dropbox.com"&gt;https://dropbox.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In order to get that working, I had to go against the documention in the dialog box and add &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt; to the dropbox.com. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; still haven't got the dropbox desktop application to work, even with *.dropbox.com in the allow list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an exercise in frustration!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 16:50:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31515#M23054</guid>
      <dc:creator>allens</dc:creator>
      <dc:date>2013-06-13T16:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: URL Allow List filters are not functioning as documented.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31516#M23055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might want to read the following Document on URL categorization that has a description on how the PAN parses URL filters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3264"&gt;https://live.paloaltonetworks.com/docs/DOC-3264&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 14:45:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31516#M23055</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-06-14T14:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: URL Allow List filters are not functioning as documented.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31517#M23056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you need allowing a domain with its subdomain you must allow them &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;domain.*&lt;/P&gt;&lt;P&gt;*.domain.*&lt;/P&gt;&lt;P&gt;*.*domain.*&lt;/P&gt;&lt;P&gt;*.*.*domain.*&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works for web-browsing, if the traffic is ssl you need to terminate it (decryptin) in order to gain full compatibility. If not only the domain.* is visible.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;In case of known application (as dropbox)&amp;nbsp; I suggest you not to use Url, use application identification, always go beyond Url Profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Jun 2013 15:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31517#M23056</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2013-06-15T15:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: URL Allow List filters are not functioning as documented.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31518#M23057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Reading that technote it really sounds odd that PA has chosen this behaviour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The common thing in the market is to separate "domain.com" from "*.domain.com" but this also means that "*.domain.com" would match "sub1.sub2.domain.com".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is to fully block for example youtube by url filter you need two url-rules:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) youtube.com (this covers http(s)://youtube.com/*)&lt;/P&gt;&lt;P&gt;2) *.youtube.com (this covers http(s)://sub1.youtube.com/* but also http(s)://sub1.sub2.youtube.com/* and so on)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could perhaps someone from PaloAlto enlighten us on this subject?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point of using url-filtering and not entirely rely on appid is what happend last xmas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://researchcenter.paloaltonetworks.com/2012/12/app-id-cache-pollution-response/" title="http://researchcenter.paloaltonetworks.com/2012/12/app-id-cache-pollution-response/"&gt;http://researchcenter.paloaltonetworks.com/2012/12/app-id-cache-pollution-response/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://researchcenter.paloaltonetworks.com/2013/01/app-id-cache-pollution-update/" title="http://researchcenter.paloaltonetworks.com/2013/01/app-id-cache-pollution-update/"&gt;http://researchcenter.paloaltonetworks.com/2013/01/app-id-cache-pollution-update/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point here is that next time appid is failing (because it most likely will otherwise there wouldnt have to be any updates for the app-db &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt; the url-filtering in the same security policy (specially if its a whitelisting rule) might save you...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is compare a security rule which only has "appid:facebook" with one that has both "appid:facebook" AND "url:facebook.com||*.facebook.com" (or whatever domains they use nowadays).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Jun 2013 22:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-allow-list-filters-are-not-functioning-as-documented/m-p/31518#M23057</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-06-15T22:38:24Z</dc:date>
    </item>
  </channel>
</rss>

