<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering Wildcards? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5984#M4353</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks James, I didn't appreciate the "." was a hard delimiter and &lt;STRONG&gt;&lt;EM&gt;had &lt;/EM&gt;&lt;/STRONG&gt;to be present.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Oct 2010 13:52:21 GMT</pubDate>
    <dc:creator>networkadmin</dc:creator>
    <dc:date>2010-10-18T13:52:21Z</dc:date>
    <item>
      <title>URL Filtering Wildcards?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5982#M4351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a custom URL category which contained&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*.sourceforge.net with an action of "allow" (the normal action for category shareware/freeware is "alert".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I visited "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://sourceforge.net"&gt;http://sourceforge.net&lt;/A&gt;&lt;SPAN&gt;" it logged an alert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had to change the custom category to contain:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*.sourceforge.net &lt;BR /&gt;sourceforge.net&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the allow to take effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was a little surprised as I expected the wildcard to include the primary domain?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 12:53:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5982#M4351</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-10-18T12:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Wildcards?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5983#M4352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wild cards work within delimeters/separators which are the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;. (dot)&lt;/P&gt;&lt;P&gt;/ (slash)&lt;/P&gt;&lt;P&gt;? (question mark)&lt;/P&gt;&lt;P&gt;&amp;amp; (ampersand)&lt;/P&gt;&lt;P&gt;= (equal)&lt;/P&gt;&lt;P&gt;; (semi colon)&lt;/P&gt;&lt;P&gt;+ (plus)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your example the *.sourceforge.net would need the . (dot) to be there for a match, which it was not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some web sites with subdomains, you may need the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;website.net&lt;/P&gt;&lt;P&gt;*.website.net&lt;/P&gt;&lt;P&gt;*.*.website.net&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps makes things clearer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 13:01:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5983#M4352</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-10-18T13:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Wildcards?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5984#M4353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks James, I didn't appreciate the "." was a hard delimiter and &lt;STRONG&gt;&lt;EM&gt;had &lt;/EM&gt;&lt;/STRONG&gt;to be present.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 13:52:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5984#M4353</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-10-18T13:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Wildcards?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5985#M4354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No worries - good luck &lt;IMG class="jive_macro jive_macro_emoticon" src="https://live.paloaltonetworks.com/resources/scripts/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 16:54:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5985#M4354</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-10-18T16:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Wildcards?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5986#M4355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So there's something I'd like to do but I'm unsure how.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now I have our Exchange server behind the PAN and policies that do SSL decryption as well as URL filtering to only allow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;site.domain.com/oma&lt;/P&gt;&lt;P&gt;site.domain.com/oma/*&lt;/P&gt;&lt;P&gt;site.domain.com/exchange&lt;/P&gt;&lt;P&gt;site.domain.com/exchange/*&lt;/P&gt;&lt;P&gt;site.domain.com/exchweb/*&lt;/P&gt;&lt;P&gt;site.domain.com/favicon.ico&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-activesync&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-servdeviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-acdeviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-actdeviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-actideviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-activdeviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-activedeviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-activesdeviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-activesync?*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-adeviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-server-deviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/microsoft-serverdeviceid=*&lt;/P&gt;&lt;P&gt;site.domain.com/public/*&lt;/P&gt;&lt;P&gt;site.domain.com/rpc/*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which are the URL's that OWA uses (all the ones in the middle are due to how the PAN seems to interpret certain URL's).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm looking at an external host monitoring service which would need to check if "site.domain.com" is up, but right now if it tries to connect it reports "Malformed response" as the PAN is blocking/not responding to the request to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://site.domain.com"&gt;https://site.domain.com&lt;/A&gt; as expected&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I add "site.domain.com" to the top of my URL allow list above, I'm basically accepting any/all requests which is precisely what I &lt;STRONG&gt;&lt;EM&gt;don't&lt;/EM&gt;&lt;/STRONG&gt; want to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how can I allow requests explicitly to "site.domain.com" but &lt;EM&gt;only &lt;/EM&gt;to "site.domain.com" as well as the paths in the list above i.e. a request to "site.domain.com/somethingrandom" would still be denied?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Oct 2010 10:28:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5986#M4355</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-10-31T10:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Wildcards?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5987#M4356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, there really is no way to do what you are trying. By adding site.domain.com/ to the allow list, it will allow all queries for items to the right of "/".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only workaround is to create a new security policy for the source IP addresses that the monitoring site uses and either allow all http traffic for that site or create a new URL filtering profile for this new security policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 18:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5987#M4356</guid>
      <dc:creator>rnitz</dc:creator>
      <dc:date>2010-11-08T18:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Wildcards?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5988#M4357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I had a feeling from experimenting that might be the case, but at least that confirms it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 18:35:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5988#M4357</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-11-08T18:35:01Z</dc:date>
    </item>
  </channel>
</rss>

