<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom URL Filtering in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/380#M305</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi bulent and achitwadgi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the replys. Sorry for not replying sooner but its been a long weekend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I chose Outlook-web, SSL and Web-Browsing. All traffic gets seen as SSL to port 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not using a certificate at the moment and yes the traffic gets seen going to the FQDN of the server (thanks for the info on the pulling of the CN from the cert) so I'll look at adding SSL decryption to pop open the traffic and see if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed that the logs generated indicated that the URL being seen is the FQDN of the server without the '/ecp' or '/owa/' so the path seems to being dropped or ignored on the request. In my custom URL filter I include the path so when I look the logs the URL is listed as 'unknown'. When I removed the path from the URL in the custom filter it gets clasified correctly as the custom URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll continue to look at the SSL decryption and how that will help but if anyones got any ideas why the paths are being ignored I'd love to here them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers for all the support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Apr 2013 22:37:12 GMT</pubDate>
    <dc:creator>TDC</dc:creator>
    <dc:date>2013-04-01T22:37:12Z</dc:date>
    <item>
      <title>Custom URL Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/377#M302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to get customer URL filtering working and it's not making much sense to me.&lt;/P&gt;&lt;P&gt;What I need to do is protect the Exchange server by allowing only connections to OWA and not ECP etc.&lt;/P&gt;&lt;P&gt;I've created a Customer URL Category called 'OWA Sites' and listed the following as sites (note there are no external URLs to go off as the external URL is currently pointing at an ISA server):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;www.xxx.yyy.zzz/owa&lt;/P&gt;&lt;P&gt;server.mydomain.co.nz/owa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've then created another Custom URL Category called 'OWA Sites Blocked' and listed the following sites:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;www.xxx.yyy.zzz/ecp&lt;/P&gt;&lt;P&gt;server.mydomain.co.nz/ecp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've then setup a URL Filtering Profile and selected 'allow' next to 'OWA Sites' and 'block' next to 'OWA Sites Blocked'&lt;/P&gt;&lt;P&gt;Finaly a rule was setup to allow the appropriate traffic to the exchange server and the new filtering profile was selected in Profile Settings section.&lt;/P&gt;&lt;P&gt;Now if I goto the site &lt;A href="http://www.xxx.yyy.zzz/owa"&gt;www.xxx.yyy.zzz/owa&lt;/A&gt; I get a security certificate error (understandable) and then get prompted to login - as planned.&lt;/P&gt;&lt;P&gt;If I go to the site &lt;A href="http://www.xxx.yyy.zzz/ecp"&gt;www.xxx.yyy.zzz/ecp&lt;/A&gt; I get the certificate error and then can log in to the ECP site. Surely the filtering profile should have blocked the site?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've then gone and set the profile type to 'none' and then used the URL filter within the services/URL category tab of the rule to see if I can control it that way but no, I can't get onto either site now.&lt;/P&gt;&lt;P&gt;Anyone got any ideas on what I'm doing wrong?&lt;/P&gt;&lt;P&gt;How are you controlling the access to the Exchange sites?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We're using 5.0.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Mar 2013 00:20:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/377#M302</guid>
      <dc:creator>TDC</dc:creator>
      <dc:date>2013-03-28T00:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/378#M303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you choose any application with that rule ?&lt;/P&gt;&lt;P&gt;When you go to both sites did you look for the traffic that both matches the same rule ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Mar 2013 07:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/378#M303</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-03-28T07:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/379#M304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do both the sites: &lt;/P&gt;&lt;P&gt;/ecp &amp;amp;/owa use the same certificate?&lt;/P&gt;&lt;P&gt;If you try to access a website over SSL, then firewall pulls the CN of the certificate and tries to apply the URL filter to it since the firewall cannot look inside the SSL tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try adding SSL decryption for traffic going to the server and see if that makes any difference?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small active_link" href="http://www.xxx.yyy.zzz/ecp" style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #316989; background-color: #ffffff;"&gt; &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Mar 2013 17:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/379#M304</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-03-28T17:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/380#M305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi bulent and achitwadgi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the replys. Sorry for not replying sooner but its been a long weekend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I chose Outlook-web, SSL and Web-Browsing. All traffic gets seen as SSL to port 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not using a certificate at the moment and yes the traffic gets seen going to the FQDN of the server (thanks for the info on the pulling of the CN from the cert) so I'll look at adding SSL decryption to pop open the traffic and see if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed that the logs generated indicated that the URL being seen is the FQDN of the server without the '/ecp' or '/owa/' so the path seems to being dropped or ignored on the request. In my custom URL filter I include the path so when I look the logs the URL is listed as 'unknown'. When I removed the path from the URL in the custom filter it gets clasified correctly as the custom URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll continue to look at the SSL decryption and how that will help but if anyones got any ideas why the paths are being ignored I'd love to here them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers for all the support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Apr 2013 22:37:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-filtering/m-p/380#M305</guid>
      <dc:creator>TDC</dc:creator>
      <dc:date>2013-04-01T22:37:12Z</dc:date>
    </item>
  </channel>
</rss>

