<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic APP vs URL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-vs-url/m-p/36419#M26774</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Despite the fact that I've blocked *.logmein.com and the logmein application, I'm still seeing traffic permitted to logmein.com. On inspecting the traffic log details, I can see that the traffic is being identified in 2 ways:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;06/21 13:07:59&amp;nbsp; THREAT&amp;nbsp; url&amp;nbsp; ssl&amp;nbsp; block-url&amp;nbsp; URL Default&amp;nbsp; Severity: informational Category: Blocked sites URL: *.app03-10.logmein.com/&lt;/P&gt;&lt;P&gt;06/21 13:09:51&amp;nbsp; TRAFFIC&amp;nbsp; end&amp;nbsp; ssl&amp;nbsp; allow&amp;nbsp; URL Default&amp;nbsp; Bytes: 8630 Packets: 18&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this because I've got SSL permitted and APP beats URL? I'd expect traffic to be denied if any part of it was being blocked, but this does not appear to be the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm thinking that SSL Decryption is the only option to stop this traffic as the logmein application is encrypted, or an explicit deny for SSL to loginme.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Jun 2010 12:56:47 GMT</pubDate>
    <dc:creator>robert.b</dc:creator>
    <dc:date>2010-06-21T12:56:47Z</dc:date>
    <item>
      <title>APP vs URL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-vs-url/m-p/36419#M26774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Despite the fact that I've blocked *.logmein.com and the logmein application, I'm still seeing traffic permitted to logmein.com. On inspecting the traffic log details, I can see that the traffic is being identified in 2 ways:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;06/21 13:07:59&amp;nbsp; THREAT&amp;nbsp; url&amp;nbsp; ssl&amp;nbsp; block-url&amp;nbsp; URL Default&amp;nbsp; Severity: informational Category: Blocked sites URL: *.app03-10.logmein.com/&lt;/P&gt;&lt;P&gt;06/21 13:09:51&amp;nbsp; TRAFFIC&amp;nbsp; end&amp;nbsp; ssl&amp;nbsp; allow&amp;nbsp; URL Default&amp;nbsp; Bytes: 8630 Packets: 18&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this because I've got SSL permitted and APP beats URL? I'd expect traffic to be denied if any part of it was being blocked, but this does not appear to be the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm thinking that SSL Decryption is the only option to stop this traffic as the logmein application is encrypted, or an explicit deny for SSL to loginme.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 12:56:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-vs-url/m-p/36419#M26774</guid>
      <dc:creator>robert.b</dc:creator>
      <dc:date>2010-06-21T12:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: APP vs URL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-vs-url/m-p/36420#M26775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rules are applied in a top down fashion - so if traffic matches an allow rule before getting to the deny rule, there will be no further matches.&amp;nbsp; Except of course, if the application or application function changes.&lt;/P&gt;&lt;P&gt;SSL Decryption does happen before the Security Policies are applied - so if the application is inside HTTPs, it will get matched correctly (assuming all other parameters are set correctly for the SSL decrypt to happen).&lt;/P&gt;&lt;P&gt;Just as a note, in case you are using the service column as well - when decrypting, you'll still see port 443 in the logs since this does not change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 17:32:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-vs-url/m-p/36420#M26775</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-06-21T17:32:27Z</dc:date>
    </item>
  </channel>
</rss>

