<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Policy Rule matches on ALL URL categories in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46117#M33882</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: left;"&gt;Try clearing the sessions for that source ip. I have got this working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;clear session all filter source &amp;lt;source ip&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 17 Aug 2013 14:31:59 GMT</pubDate>
    <dc:creator>harshanatarajan</dc:creator>
    <dc:date>2013-08-17T14:31:59Z</dc:date>
    <item>
      <title>Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46108#M33873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm sure this was working at some stage but now it's not working the way I need it: I have a rule from inside to outside, any user, web-browsing and a URL category of gambling, allow the traffic and use log forwarding with no profiles selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that the URL is matched on ANY traffic. Doing a 'test url' from the command line lists them as " computer-and-internet-info" and the url-cache is looking good. The box is licensed for PAN-DB as well. Any idea what I'm doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 12:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46108#M33873</guid>
      <dc:creator>hoerzers</dc:creator>
      <dc:date>2013-08-16T12:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46109#M33874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you create a URL filtering profile,&amp;nbsp; setting the action to "alert" for&amp;nbsp; "gambling", and applying the URL filtering profile to the rule, instead of matching the URL category of gambling on the rule itself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 13:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46109#M33874</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-16T13:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46110#M33875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here a couple of useful links that explain why creating the URL filtering profile is preferred over adding the category on the rule itself&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/message/28646#28646"&gt;https://live.paloaltonetworks.com/message/28646#28646&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/message/23810#23810"&gt;https://live.paloaltonetworks.com/message/23810#23810&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-3108"&gt;https://live.paloaltonetworks.com/docs/DOC-3108&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 13:30:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46110#M33875</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-16T13:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46111#M33876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If i understand it correctly&lt;/P&gt;&lt;P&gt;1. you have PAN-DB URL filtering license&lt;/P&gt;&lt;P&gt;2. In the policy you have gambling as URL category&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;The URL that you are going to is it suppose to be categorized as gambling or it is indeed "&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;computer-and-internet-info" . If it is gambling then you can request a URL categorization change request. &lt;BR /&gt;&lt;/SPAN&gt;Since the URL is not being identified correctly. You can go to the following site to do that&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri','sans-serif'; color: black;"&gt;(&lt;A href="http://urlfiltering.paloaltonetworks.com/testASite.aspx"&gt;http://urlfiltering.paloaltonetworks.com/testASite.aspx&lt;/A&gt;) or i believe you can also do it directly from the device as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri','sans-serif'; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri','sans-serif'; color: black;"&gt;If that is not the case and the site you are going to is &lt;/SPAN&gt;"&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;computer-and-internet-info" and that is what the test url command is showing but in the traffic policy we are not hitting it correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Then you can try to clear the cache by using the following commands and then test if it is hitting the correct policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;“clear url-cache url &amp;lt;URL&amp;gt;” &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt; “delete url-database url &amp;lt;URL&amp;gt;”&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt; Next time the device will ask for the category of this URL, the request will be forwarded&amp;nbsp; to the cloud.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Let us know if this helps you resolve the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Numan&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 19:12:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46111#M33876</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-16T19:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46112#M33877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that I can use the profiles but what I'm really trying to find out why this doesn't work with the URL category straight in the rule itself. The URL is www.microsoft.com and correctly identified as "&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;"&lt;/SPAN&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;computer-and-internet-info". The same thing happens for www.intel.com. I've changed the category to 'adult' and still the same. I've cleared the entire URL cache and deleted the URL database and the rule is still incorrectly triggered. Below is the rule and a log entry for intel.com.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;BTW, I've tried this on another PA-200, also 5.0.5 with a similar result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;IMG alt="rule.PNG" class="jive-image-thumbnail jive-image" height="39" src="https://live.paloaltonetworks.com/legacyfs/online/7742_rule.PNG" style="height: 39.166666666666664px; width: 1175px;" width="1175" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="log.PNG" class="jive-image-thumbnail jive-image" height="33" src="https://live.paloaltonetworks.com/legacyfs/online/7741_log.PNG" style="height: 33px; width: 1142.3076923076924px;" width="1142" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 23:45:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46112#M33877</guid>
      <dc:creator>hoerzers</dc:creator>
      <dc:date>2013-08-16T23:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46113#M33878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you had a look at this discussion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/16814#16814"&gt;https://live.paloaltonetworks.com/message/16814#16814&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Aug 2013 04:56:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46113#M33878</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2013-08-17T04:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46114#M33879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have now but unfortunately it does not solve my problem. I really need to know why something like Intel.com triggers the test rule I created. I understand the logging part but I don't understand why the rule does not work as expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Aug 2013 06:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46114#M33879</guid>
      <dc:creator>hoerzers</dc:creator>
      <dc:date>2013-08-17T06:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46115#M33880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is expected behaviour.I know it seems like an issue but using url category is not a good solution.You see incomplete in the log you attached.Here is the explanation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Incomplete means we have not had enough packets to identify the application being used in the session. When this happens we will use the first policy match that will match the source and destination zones and IP's and then the service (port numbers) this has to be done for enough of the packets to go through and then let us apply the rules per application, this is also true for the URL filtering, until we know the application we can't apply these rules to the traffic."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Aug 2013 12:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46115#M33880</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-17T12:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46116#M33881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Understood. Thanks for the explanation!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Aug 2013 13:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46116#M33881</guid>
      <dc:creator>hoerzers</dc:creator>
      <dc:date>2013-08-17T13:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46117#M33882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: left;"&gt;Try clearing the sessions for that source ip. I have got this working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;clear session all filter source &amp;lt;source ip&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Aug 2013 14:31:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46117#M33882</guid>
      <dc:creator>harshanatarajan</dc:creator>
      <dc:date>2013-08-17T14:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule matches on ALL URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46118#M33883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;not to see incomplete or etc.. applications hitting that rule only way is to change that rule's logging to session start( not end.) otherwise alhough you clear all sessions this behaviour will not change, you will see unexpected traffic hitting that url category - web browsing rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Aug 2013 16:11:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-matches-on-all-url-categories/m-p/46118#M33883</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-17T16:11:51Z</dc:date>
    </item>
  </channel>
</rss>

