<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-500 Url Filtering in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67214#M39468</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you verify this counter&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show counter global filter | match url_request_pkt_drop&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you obtain something like this&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;url_request_pkt_drop&amp;nbsp;&amp;nbsp;&amp;nbsp; 334056 &amp;nbsp; 10 drop&amp;nbsp;&amp;nbsp; url&amp;nbsp;&amp;nbsp; pktproc&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if you have some drop packet it's du to the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;waiting time for url categorisation &amp;nbsp;request&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to resolve this&lt;/P&gt;
&lt;P&gt;modify this parameter&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; set deviceconfig setting ctd url-wait-timeout&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;and define a value greater than 5 and less than 60&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by default panos use a value of 5 s and &amp;nbsp;the PA-500 is to light to process the categorisation and takeover the limit of 5s&lt;/P&gt;
&lt;P&gt;you and increase the capacity of the PA-500 but increase the acceptable time to resolve the query&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regard's&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can find more info&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/What-is-the-Cause-of-Packets-Dropped-Due-to-URL-Look-Up-Failure/ta-p/59703" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/What-is-the-Cause-of-Packets-Dropped-Due-to-URL-Look-Up-Failure/ta-p/59703&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Oct 2015 15:31:30 GMT</pubDate>
    <dc:creator>Gregoux</dc:creator>
    <dc:date>2015-10-23T15:31:30Z</dc:date>
    <item>
      <title>PA-500 Url Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67068#M39413</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;i have another problem with policies...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I used AD to filter people which can access the appropriate site.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And I have rule in order:&lt;/P&gt;
&lt;P&gt;1. Allow facebook (when I give access to whole facebook application)&lt;/P&gt;
&lt;P&gt;2. Allow Youtube (when I use url filtering)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my opinion when user who is in group allow_facebook and allow_youtube and want to open the facebook site are using first rule and can open the site?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in my network this user use second rule and he has information about blocked site....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know what I do wrong..&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 06:18:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67068#M39413</guid>
      <dc:creator>ITBT</dc:creator>
      <dc:date>2015-10-22T06:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA-500 Url Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67070#M39414</link>
      <description>&lt;P&gt;check from CLI that said user is really in allow_facebook group if the rule is not applying to him.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 08:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67070#M39414</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-10-22T08:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA-500 Url Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67124#M39429</link>
      <description>&lt;P&gt;Is the rule/application it specifically for Facebook-BASE&lt;/P&gt;
&lt;P&gt;Does that first rule allow the traffic for another user?&lt;/P&gt;
&lt;P&gt;in otherwords can another user from the approved 'AD OU' group get to the site&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you want to determine is it a user issue or a security policy issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you look in the logs afterward - filter by user name and see which policy that traffic is hitting&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 14:07:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67124#M39429</guid>
      <dc:creator>DarinSutton</dc:creator>
      <dc:date>2015-10-22T14:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: PA-500 Url Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67214#M39468</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you verify this counter&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show counter global filter | match url_request_pkt_drop&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you obtain something like this&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;url_request_pkt_drop&amp;nbsp;&amp;nbsp;&amp;nbsp; 334056 &amp;nbsp; 10 drop&amp;nbsp;&amp;nbsp; url&amp;nbsp;&amp;nbsp; pktproc&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if you have some drop packet it's du to the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;waiting time for url categorisation &amp;nbsp;request&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to resolve this&lt;/P&gt;
&lt;P&gt;modify this parameter&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; set deviceconfig setting ctd url-wait-timeout&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;and define a value greater than 5 and less than 60&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by default panos use a value of 5 s and &amp;nbsp;the PA-500 is to light to process the categorisation and takeover the limit of 5s&lt;/P&gt;
&lt;P&gt;you and increase the capacity of the PA-500 but increase the acceptable time to resolve the query&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regard's&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can find more info&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/What-is-the-Cause-of-Packets-Dropped-Due-to-URL-Look-Up-Failure/ta-p/59703" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/What-is-the-Cause-of-Packets-Dropped-Due-to-URL-Look-Up-Failure/ta-p/59703&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 15:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-url-filtering/m-p/67214#M39468</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2015-10-23T15:31:30Z</dc:date>
    </item>
  </channel>
</rss>

