<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic URL-Filtering: Use profiles or specify categories in rules? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37334#M27372</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are two ways to select which URL categories should be allowed/blocked: You can either create a URL-Filtering profile and attach it to firewall rules, or you can specify URL-categories directly in the firewall rule (destination). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifying URL categories directly in the firewall rule seems to have the advantage that you can immediately see which categories you allow/block directly in the rulebase, without looking into the profiles. Then again, using profiles seems to have the advantage that you can specify more actions (override, alarm etc.). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the general approach here? Why would you choose one over the other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what would happen if I would combine both approaches? e.g. Specify some destination URL categories in a firewall block rule and then add a profile that allows and logs all categories? Which takes precedence? Is it even possible to combine in such a way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your thoughts!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Jun 2013 17:39:41 GMT</pubDate>
    <dc:creator>cryptochrome</dc:creator>
    <dc:date>2013-06-19T17:39:41Z</dc:date>
    <item>
      <title>URL-Filtering: Use profiles or specify categories in rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37334#M27372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are two ways to select which URL categories should be allowed/blocked: You can either create a URL-Filtering profile and attach it to firewall rules, or you can specify URL-categories directly in the firewall rule (destination). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifying URL categories directly in the firewall rule seems to have the advantage that you can immediately see which categories you allow/block directly in the rulebase, without looking into the profiles. Then again, using profiles seems to have the advantage that you can specify more actions (override, alarm etc.). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the general approach here? Why would you choose one over the other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what would happen if I would combine both approaches? e.g. Specify some destination URL categories in a firewall block rule and then add a profile that allows and logs all categories? Which takes precedence? Is it even possible to combine in such a way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your thoughts!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 17:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37334#M27372</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-19T17:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: URL-Filtering: Use profiles or specify categories in rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37335#M27373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can use url filtering profiles with allow/block list option, can take different actions for different categories, logged in url filtering log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can user url category only pre-defined category or custom, logged as security log(if enabled),can be used with security policies,qos,decryption or captive portal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 17:57:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37335#M27373</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-19T17:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: URL-Filtering: Use profiles or specify categories in rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37336#M27374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I almost always use the Security Profiles when it comes to URL filtering enforcement.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe one of the down-sides of using the URL Category directly in the rule itself with a "block" action is that you won't get a block "response page" when something is blocked.&amp;nbsp; I believe the firewall treats this like a regular traffic drop.&amp;nbsp; That's liable to generate more support calls as the users don't know why something isn't working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only time I have used URL Categories directly in a rule is when you want to use different Security Profiles that are based on the URL Category.&amp;nbsp; Here's a good example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's say your organization has a URL filtering profile that allows these two URL categories:&lt;/P&gt;&lt;P&gt;- computers-and-internet-info&lt;/P&gt;&lt;P&gt;- games&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, you wish to block all .EXE downloads from the games category.&amp;nbsp; In order to do this, you create two firewall rules:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from trust to untrust, application=web-browsing, URL_Category=games, action=allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; - SecurityProfile / File Blocking / Block EXE files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; - SecurityProfile / URL Filtering / Company_URL_Profile&lt;/P&gt;&lt;P&gt;from trust to untrust, application=web-browsing, URL_Category=any, action=allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; - SecurityProfile / File Blocking / Permit&amp;amp;Log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; - SecurityProfile / URL Filtering / Company_URL_Profile&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way if you go to a games website, and download an EXE, it'll get blocked based on the first rule.&amp;nbsp; If you're surfing to any other allowed URL category, then your traffic matches against the 2nd rule, which permits &amp;amp; logs EXE downloads. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the first rule, you're not technically using the Company_URL_Profile for enforcement, as no other URL categories will be matched by that rule.&amp;nbsp; However, if you wish to have the gaming URLs logged, then you need to attach the URL Filtering profile - this profile would need games=alert in order for those URLs to be logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's the only time I've used the URL Category in the rule itself - when I've needed to use different security profiles on a per-URL-category-basis. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 18:16:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37336#M27374</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-06-19T18:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: URL-Filtering: Use profiles or specify categories in rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37337#M27375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. Can you rephrase your second sentence? I am not quite getting it &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 18:54:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37337#M27375</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-19T18:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: URL-Filtering: Use profiles or specify categories in rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37338#M27376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, jvalentine. Good point about no proper response pages when using categories in a block rule directly. Is this verified?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the rest of you response: Great, thanks. That helped a lot. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 18:56:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37338#M27376</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-19T18:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: URL-Filtering: Use profiles or specify categories in rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37339#M27377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JValentine is correct.&amp;nbsp; When you use a URL category in your security rule (as opposed to a URL filtering profile), the only actions you have are allow or block.&amp;nbsp; So if you want to log and/or use a custom response page (block page, continue page, override), you will need to use a URL filtering profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 20:19:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37339#M27377</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2013-06-19T20:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: URL-Filtering: Use profiles or specify categories in rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37340#M27378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Edited to read:&amp;nbsp; I believe one of the down-sides of using the URL Category directly in the rule itself with a "block" action is that you won't get a block "response page" when something is blocked. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 23:30:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37340#M27378</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-06-19T23:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: URL-Filtering: Use profiles or specify categories in rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37341#M27379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh I understood your second sentence, jvalentine. My reply about not quite getting it was directed at panos (first reply in the thread). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks everyone. I get it now. I am going to use profiles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 07:54:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-use-profiles-or-specify-categories-in-rules/m-p/37341#M27379</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-20T07:54:42Z</dc:date>
    </item>
  </channel>
</rss>

