<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Subnet entry in Custom URL Category in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/subnet-entry-in-custom-url-category/m-p/35201#M25865</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To block the subnet the correct way is to block at dstip and not dsturl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However even if a real browser shouldnt be able to connect to a different ip than the one stated in the url request (I mean if you type &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://5.6.7.8/"&gt;http://5.6.7.8/&lt;/A&gt;&lt;SPAN&gt; in your browser the browser will try to connect to dstip 5.6.7.8) there could be various malwares and possible other cases of where http is being used as a protocol but where the dstip is for example 1.2.3.4 but the requested url is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://5.6.7.8/"&gt;http://5.6.7.8/&lt;/A&gt;&lt;SPAN&gt; for a particular request (or "Host: 5.6.7.8" for that matter).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A question related to this, does PA have a IPS-signature against if a client performs a request towards dstip 1.2.3.4 but the url requested is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://5.6.7.8/"&gt;http://5.6.7.8/&lt;/A&gt;&lt;SPAN&gt; (or rather "Host: 5.6.7.8") and is this signature valid for both IPv4 and IPv6?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Aug 2012 21:17:08 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-08-29T21:17:08Z</dc:date>
    <item>
      <title>Subnet entry in Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subnet-entry-in-custom-url-category/m-p/35200#M25864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;If I were to enter multiple subnets (ex: 218.65.30.0/24) as entries in a Custom URL Category, will those entries been seen as the entire subnet or will they be seen as a URL (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://218.65.30.0/24"&gt;http://218.65.30.0/24&lt;/A&gt;&lt;SPAN&gt;)?&amp;nbsp; I ask this because I'm looking at creating an outbound block/deny policy based off custom URL categories and I want to make sure I am actually blocking this entire subnet.&amp;nbsp; I am also looking at the possibility of creating this list as a Region and then blocking that region.&amp;nbsp; It seems silly to create an address object for each one and then add them all to an address group, which I know can be done automatically through scripting to save time, but I was wondering if the above scenario would do what I need.&amp;nbsp; Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2012 17:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subnet-entry-in-custom-url-category/m-p/35200#M25864</guid>
      <dc:creator>sconley</dc:creator>
      <dc:date>2012-08-29T17:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet entry in Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subnet-entry-in-custom-url-category/m-p/35201#M25865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To block the subnet the correct way is to block at dstip and not dsturl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However even if a real browser shouldnt be able to connect to a different ip than the one stated in the url request (I mean if you type &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://5.6.7.8/"&gt;http://5.6.7.8/&lt;/A&gt;&lt;SPAN&gt; in your browser the browser will try to connect to dstip 5.6.7.8) there could be various malwares and possible other cases of where http is being used as a protocol but where the dstip is for example 1.2.3.4 but the requested url is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://5.6.7.8/"&gt;http://5.6.7.8/&lt;/A&gt;&lt;SPAN&gt; for a particular request (or "Host: 5.6.7.8" for that matter).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A question related to this, does PA have a IPS-signature against if a client performs a request towards dstip 1.2.3.4 but the url requested is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://5.6.7.8/"&gt;http://5.6.7.8/&lt;/A&gt;&lt;SPAN&gt; (or rather "Host: 5.6.7.8") and is this signature valid for both IPv4 and IPv6?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2012 21:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subnet-entry-in-custom-url-category/m-p/35201#M25865</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-29T21:17:08Z</dc:date>
    </item>
  </channel>
</rss>

