<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No way to view sites that are set to &amp;quot;Allow&amp;quot;? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37066#M27204</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Reviving very old post but nowhere else can I find anything similar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how does this work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rule is that "When a user attempts to access a URL and the URL category needs to be determined, the firewall will compare the URL with the following components until a match has been found:&lt;/P&gt;&lt;P&gt;1. Block list of the matching URL profile&lt;/P&gt;&lt;P&gt;2. Allow list of the matching URL profile&lt;/P&gt;&lt;P&gt;3. Custom categories that have been defined&lt;/P&gt;&lt;P&gt;4. DP URL cache&lt;/P&gt;&lt;P&gt;5. MP URL cache&lt;/P&gt;&lt;P&gt;6. Cloud systems"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If Allow takes precedence over Custom categories, how can you see the allowed sites?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e. if I put *.facebook.com and facebook.com in the URL Filtering Allow list, and also add them to a custom URL category called "show_me_allowed", and set the custom Alert Category list to be "Alert", when i browse to Facebook and look at the URL log, I still cannot see it because Allow supersedes Custom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Theoretically: How do we prove that a user who is allowed to access a site during work hours also accessed (or didn't) the site at other times if we can't see it? We do not use the PaloAlto schedules feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Jan 2014 20:29:33 GMT</pubDate>
    <dc:creator>hvcomputech</dc:creator>
    <dc:date>2014-01-10T20:29:33Z</dc:date>
    <item>
      <title>No way to view sites that are set to "Allow"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37062#M27200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way to view sites that are set to "Allow" or are in the "Allow list"? I can see the "Allow list" sites via the Application Command Center, but is there any way to view them in the "Monitor" tab or through reporting?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Mar 2011 15:35:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37062#M27200</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2011-03-31T15:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: No way to view sites that are set to "Allow"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37063#M27201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are talking about the URL Filter&lt;/P&gt;&lt;P&gt;set them to "Alert" instead of "Allow"&lt;/P&gt;&lt;P&gt;Then they are logged under Monitor - URL Filtering&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Mar 2011 15:40:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37063#M27201</guid>
      <dc:creator>ExclusiveNetworksGermany</dc:creator>
      <dc:date>2011-03-31T15:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: No way to view sites that are set to "Allow"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37064#M27202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;TLK Support wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are talking about the URL Filter&lt;/P&gt;&lt;P&gt;set them to "Alert" instead of "Allow"&lt;/P&gt;&lt;P&gt;Then they are logged under Monitor - URL Filtering&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've actually tried this, but our SIEM(qradar) does not like it.&amp;nbsp; It will send all allowed sites to qradar as an Alert, which ultimately generates a lot of false offenses.&amp;nbsp; Also, that method won't show me sites that I specify in the "allow list sites".&amp;nbsp; I don't understand why we can view allowed sites in the ACC, but not anywhere else.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Mar 2011 16:39:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37064#M27202</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2011-03-31T16:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: No way to view sites that are set to "Allow"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37065#M27203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this happens because the "allow" action on URL categories does not create log entries, but the ACC collects both information from logging and the dataplane, so recently accessed allowed sites will have sessions generated and result in an entry in the ACC&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you want to be able to set sites you currently have in your allow list to "alert" you can create a custom category and add these sites to it, then you will be able to have these sites handled like other categories (allow, alert, block, continue, override)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Apr 2011 09:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37065#M27203</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-04-01T09:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: No way to view sites that are set to "Allow"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37066#M27204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Reviving very old post but nowhere else can I find anything similar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how does this work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rule is that "When a user attempts to access a URL and the URL category needs to be determined, the firewall will compare the URL with the following components until a match has been found:&lt;/P&gt;&lt;P&gt;1. Block list of the matching URL profile&lt;/P&gt;&lt;P&gt;2. Allow list of the matching URL profile&lt;/P&gt;&lt;P&gt;3. Custom categories that have been defined&lt;/P&gt;&lt;P&gt;4. DP URL cache&lt;/P&gt;&lt;P&gt;5. MP URL cache&lt;/P&gt;&lt;P&gt;6. Cloud systems"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If Allow takes precedence over Custom categories, how can you see the allowed sites?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e. if I put *.facebook.com and facebook.com in the URL Filtering Allow list, and also add them to a custom URL category called "show_me_allowed", and set the custom Alert Category list to be "Alert", when i browse to Facebook and look at the URL log, I still cannot see it because Allow supersedes Custom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Theoretically: How do we prove that a user who is allowed to access a site during work hours also accessed (or didn't) the site at other times if we can't see it? We do not use the PaloAlto schedules feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 20:29:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37066#M27204</guid>
      <dc:creator>hvcomputech</dc:creator>
      <dc:date>2014-01-10T20:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: No way to view sites that are set to "Allow"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37067#M27205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You wouldn't want to put it in both an allow list and an alert custom category.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead, remove them from the allow list and make them only exist in the custom URL category for which you have set them to alert. That way when it goes through the #2 on your list, it won't see facebook.com, and will then got to #3 hitting the Alert action on that custom category.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 20:47:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37067#M27205</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2014-01-10T20:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: No way to view sites that are set to "Allow"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37068#M27206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll try that, thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 15:13:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-way-to-view-sites-that-are-set-to-quot-allow-quot/m-p/37068#M27206</guid>
      <dc:creator>hvcomputech</dc:creator>
      <dc:date>2014-01-13T15:13:34Z</dc:date>
    </item>
  </channel>
</rss>

