<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hybrid whitelist/blacklist Policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/63592#M38243</link>
    <description>&lt;P&gt;You could just create a DNS black list on your DNS server that points some place else for all of those sites its an internal address it won't hit your firewall.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Aug 2015 12:52:45 GMT</pubDate>
    <dc:creator>murphyj</dc:creator>
    <dc:date>2015-08-25T12:52:45Z</dc:date>
    <item>
      <title>Hybrid whitelist/blacklist Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39410#M28919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I played around on our lab FW a bit but couldn't get this working. Here are my objectives:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Create a "White List" custom URL category that allows only a handful of web sites. (Working with URL Filtering profile.)&lt;/P&gt;&lt;P&gt;- Log all permits (Working. I got this by setting Action to alert)&lt;/P&gt;&lt;P&gt;- Create a "Black List" custom URL category that denies a bunch of "noisy" URLs without logging. &lt;/P&gt;&lt;P&gt;- Log all other denies (Working. I got this at the very end of my rules)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The goal is to create a log noise reducing rule so I can see denies that matter to me. I have tried several variations of rules and defining a separate URL policy. So far not much luck. Any tips for accomplishing this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 22:23:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39410#M28919</guid>
      <dc:creator>russ.starr</dc:creator>
      <dc:date>2013-10-09T22:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Hybrid whitelist/blacklist Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39411#M28920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you look at your traffic log, there is a column that shows the rule that is being hit. Do you see your Black List rule listed or is that rule being missed and it's instead hitting the bottom rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally, this should work the way you mention. The one caveat I can think of is the URL filtering logs. Those logs will show up no matter what, as a deny is a log action. There is no concept of denying a URL category and not logging it to the URL filtering rules. You may be able to get this to work by not using the URL filtering profile and instead selecting the categories in the rule itself with a deny action and unchecking the logging options on that rule, but I have not tried doing so yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 23:27:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39411#M28920</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-10-09T23:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Hybrid whitelist/blacklist Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39412#M28921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, if you put security rule with black list on top - without option log - it should avoid too many logs.&lt;/P&gt;&lt;P&gt;e.g. create custom category with black list as custom-deny-no log&lt;/P&gt;&lt;P&gt;add a security rule to block traffic with custom category and put it on top.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="9017" alt="1-.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9017_1-.PNG.png" style="width: 620px; height: 344px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 23:30:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39412#M28921</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2013-10-09T23:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Hybrid whitelist/blacklist Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39413#M28922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you both for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added a line that proceeds my URL Whitelist Policy line that has a blacklist line like you indicated. It has a custom URL category defined, denies traffic, and is set to not log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am passing traffic through and it is getting denied, however it gets logged and never gets matched by the rule I created. I'm still troubleshooting but source/dest zone IP (any), category, application/service, and everything _should_ be matching it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 20:08:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39413#M28922</guid>
      <dc:creator>russ.starr</dc:creator>
      <dc:date>2013-10-10T20:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Hybrid whitelist/blacklist Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39414#M28923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Probably the quickest work around for my solution is to add the following expression to my log viewing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ( category neq 'URL Blacklist' )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I can deal with that for now. Deny with no log would be icing on the cake but unless someone has a quick fix I'll leave it at that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 20:23:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/39414#M28923</guid>
      <dc:creator>russ.starr</dc:creator>
      <dc:date>2013-10-10T20:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Hybrid whitelist/blacklist Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/63592#M38243</link>
      <description>&lt;P&gt;You could just create a DNS black list on your DNS server that points some place else for all of those sites its an internal address it won't hit your firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 12:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hybrid-whitelist-blacklist-policy/m-p/63592#M38243</guid>
      <dc:creator>murphyj</dc:creator>
      <dc:date>2015-08-25T12:52:45Z</dc:date>
    </item>
  </channel>
</rss>

