<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow one URL out of many sharing an IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-one-url-out-of-many-sharing-an-ip/m-p/67826#M39682</link>
    <description>&lt;P&gt;allowing access to the FQDN (through an FQDN address object) will open access to the IP rather than the URL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can resolve this by creating a custom category containing the url, then use that category in the security policy's service/URLcategory tab, then a second rule below that, that drops all other traffic to that IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1113iCDD1A3283F015E8A/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-11-09_09-22-21.png" title="2015-11-09_09-22-21.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2015 08:25:07 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2015-11-09T08:25:07Z</dc:date>
    <item>
      <title>Allow one URL out of many sharing an IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-one-url-out-of-many-sharing-an-ip/m-p/67757#M39663</link>
      <description>&lt;P&gt;We're faced with a bit of a challenge. We blocked a GoDaddy-Hosting IP for sending malicious traffic to our campus. Faculty later complained that a site they rely on is hosted with the same IP. I've attempted many different configurations with IP filtering, URL whitelisting etc, but can't quite arrive at a simple working solution (Plan B is blacklisting every other known URL that shares the IP... not elegant). We'd like to block traffic to and from that IP and campus, but allow connections to be made from within campus to the one legitimate URL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 18:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-one-url-out-of-many-sharing-an-ip/m-p/67757#M39663</guid>
      <dc:creator>rcaduser</dc:creator>
      <dc:date>2015-11-06T18:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Allow one URL out of many sharing an IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-one-url-out-of-many-sharing-an-ip/m-p/67773#M39668</link>
      <description>&lt;P&gt;So your users need to access one website on this bad IP?&lt;/P&gt;
&lt;P&gt;Why don't you create rule to allow traffic to that FQDN and then second rule below that to block any traffic towards that bad IP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 00:17:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-one-url-out-of-many-sharing-an-ip/m-p/67773#M39668</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-11-07T00:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Allow one URL out of many sharing an IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-one-url-out-of-many-sharing-an-ip/m-p/67826#M39682</link>
      <description>&lt;P&gt;allowing access to the FQDN (through an FQDN address object) will open access to the IP rather than the URL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can resolve this by creating a custom category containing the url, then use that category in the security policy's service/URLcategory tab, then a second rule below that, that drops all other traffic to that IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1113iCDD1A3283F015E8A/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-11-09_09-22-21.png" title="2015-11-09_09-22-21.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 08:25:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-one-url-out-of-many-sharing-an-ip/m-p/67826#M39682</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-11-09T08:25:07Z</dc:date>
    </item>
  </channel>
</rss>

