<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with &amp;quot;Deny All, with whitelist of domains&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75489#M41999</link>
    <description>&lt;P&gt;For DNS domain based rules, you better use the URL filtering functionality. You could create a custom URL category and add all necessary domains to it. Then only allow this custom URL category. This also works without URL filtering license.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2016 18:50:40 GMT</pubDate>
    <dc:creator>Anon1</dc:creator>
    <dc:date>2016-03-30T18:50:40Z</dc:date>
    <item>
      <title>Help with "Deny All, with whitelist of domains"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75483#M41997</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have been trying to test out a new policy that will need to be implemented by our security team. This involves a Deny All rule, with a rule right above it that allows a list of domains. These domains include SaaS services, Cloud, and other domains that users must access to achieve daily production.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have tried to make the whitelist based on FQDNs, but I am running into a problem when we have CDNs that are embedded in the destined location. I was able to monitor the 3rd party content and whitelist those URLs as well, but we are still having and issue when some of the domains might have some type of GLB on their end. The PAN does cache 10 IP addresses per FQDN at a time, but I'm afraid that it might not be enough.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have discussed the options of a web proxy, but I am just curious if anybody has any better ideas on achieving this end goal, specifically with the PAN.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 17:51:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75483#M41997</guid>
      <dc:creator>kaboom</dc:creator>
      <dc:date>2016-03-30T17:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Help with "Deny All, with whitelist of domains"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75489#M41999</link>
      <description>&lt;P&gt;For DNS domain based rules, you better use the URL filtering functionality. You could create a custom URL category and add all necessary domains to it. Then only allow this custom URL category. This also works without URL filtering license.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 18:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75489#M41999</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2016-03-30T18:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Help with "Deny All, with whitelist of domains"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75496#M42001</link>
      <description>&lt;P&gt;When I spoke to PAN, URL Filtering only applies to HTTP and HTTPS traffic.&amp;nbsp;Therefore, I don't think that it would work for&amp;nbsp;applications.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 19:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75496#M42001</guid>
      <dc:creator>kaboom</dc:creator>
      <dc:date>2016-03-30T19:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help with "Deny All, with whitelist of domains"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75498#M42002</link>
      <description>&lt;P&gt;That´s right, I assumed it were web based applications which are accessed via HTTP/HTTPS. Maybe there is an AppID signature for your particular applications? Do you have examples?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 19:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-quot-deny-all-with-whitelist-of-domains-quot/m-p/75498#M42002</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2016-03-30T19:33:57Z</dc:date>
    </item>
  </channel>
</rss>

