<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule too allow access to group of URLs? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122162#M46110</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;I'm getting confused by what you're saying you're trying to do and how you're creating a policy to accomplish that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You said you created a security policy with ANY source / dest / application. &amp;nbsp;That uses service http/https.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm curious about is are you using a custom URL object within the security policy on the "services" tab, or are you using a URL profile with the custom URL object you're referring to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you've got an any / any /any rule it's natural for the other traffic to match this rule. &amp;nbsp;It's only until the domain matching occurs&amp;nbsp;that traffic would transition to a different rule in your firewall. &amp;nbsp;All that other "random stuff" you reference is occurring&amp;nbsp;over ports 80 and 443 so it initially matches.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks for the reply and hopefully this will clarify.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm adding the URL category to the Service/URL category tab on the security policy rule.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Oct 2016 19:00:19 GMT</pubDate>
    <dc:creator>networkadmin</dc:creator>
    <dc:date>2016-10-28T19:00:19Z</dc:date>
    <item>
      <title>Rule too allow access to group of URLs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/120427#M45914</link>
      <description>&lt;P&gt;PANOS 7.0.4 and I'm struggling to do something that feels basic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to allow anything on the LAN access to&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;*.sophos.com&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;*.sophosupd.com&lt;/LI&gt;&lt;LI&gt;*.sophosupd.net&lt;/LI&gt;&lt;LI&gt;*.sophosxl.net&lt;/LI&gt;&lt;LI&gt;ocsp2.globalsign.com&lt;/LI&gt;&lt;LI&gt;crl.globalsign.com&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;as per&amp;nbsp;&lt;A href="https://community.sophos.com/kb/en-us/121936" target="_blank"&gt;https://community.sophos.com/kb/en-us/121936&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now we use captive portal but of course machines might try to update when nobody is logged in on them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't add "address" objects for entire domains (can I?!) and if I add a URL category and create a rule at the top of my ruleset that allow source "any" to destination "any" with service-http, service-https and application "any", and add the URL category that contans the domains above, I seem to see a lot of matches that I wouldn't expect to, as if other traffic is hitting them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feels like I've overlooked something daft... thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 14:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/120427#M45914</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-10-21T14:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Rule too allow access to group of URLs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/120467#M45929</link>
      <description>&lt;P&gt;Maybe you can use the AppID "sophos-update" with service "application-default" and URL category "any"?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 20:17:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/120467#M45929</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2016-10-21T20:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Rule too allow access to group of URLs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/121550#M46064</link>
      <description>&lt;P&gt;Thanks but that doesn't work, I guess Sophos Central isn't quite the same app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using the URL filter on a rule that only applies to my own PC I'm seeing Dropbox and other random stuff match the rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tbh I didn't expect that something that on paper looks so simple would prove so difficult for a Palo Alto box.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 19:21:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/121550#M46064</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-10-26T19:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Rule too allow access to group of URLs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122034#M46097</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1862"&gt;@networkadmin&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;...if I add a URL category and create a rule at the top of my ruleset that allow source "any" to destination "any" with service-http, service-https and application "any", and add the URL category that contans the domains above, I seem to see a lot of matches that I wouldn't expect to, as if other traffic is hitting them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feels like I've overlooked something daft... thanks!&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How are you "adding the URL categpry?" &amp;nbsp;Are you adding it in the security policy or in a URL profile?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 13:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122034#M46097</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-10-28T13:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Rule too allow access to group of URLs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122065#M46102</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt; wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1862"&gt;@networkadmin&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;...if I add a URL category and create a rule at the top of my ruleset that allow source "any" to destination "any" with service-http, service-https and application "any", and add the URL category that contans the domains above, I seem to see a lot of matches that I wouldn't expect to, as if other traffic is hitting them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feels like I've overlooked something daft... thanks!&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How are you "adding the URL categpry?" &amp;nbsp;Are you adding it in the security policy or in a URL profile?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Trying on the security policy as if I try adding on a URL profile it would have the effect of blocking everything else.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 14:08:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122065#M46102</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-10-28T14:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Rule too allow access to group of URLs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122161#M46109</link>
      <description>&lt;P&gt;&amp;nbsp;I'm getting confused by what you're saying you're trying to do and how you're creating a policy to accomplish that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You said you created a security policy with ANY source / dest / application. &amp;nbsp;That uses service http/https.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm curious about is are you using a custom URL object within the security policy on the "services" tab, or are you using a URL profile with the custom URL object you're referring to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you've got an any / any /any rule it's natural for the other traffic to match this rule. &amp;nbsp;It's only until the domain matching occurs&amp;nbsp;that traffic would transition to a different rule in your firewall. &amp;nbsp;All that other "random stuff" you reference is occurring&amp;nbsp;over ports 80 and 443 so it initially matches.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 18:43:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122161#M46109</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-10-28T18:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Rule too allow access to group of URLs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122162#M46110</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;I'm getting confused by what you're saying you're trying to do and how you're creating a policy to accomplish that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You said you created a security policy with ANY source / dest / application. &amp;nbsp;That uses service http/https.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm curious about is are you using a custom URL object within the security policy on the "services" tab, or are you using a URL profile with the custom URL object you're referring to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you've got an any / any /any rule it's natural for the other traffic to match this rule. &amp;nbsp;It's only until the domain matching occurs&amp;nbsp;that traffic would transition to a different rule in your firewall. &amp;nbsp;All that other "random stuff" you reference is occurring&amp;nbsp;over ports 80 and 443 so it initially matches.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks for the reply and hopefully this will clarify.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm adding the URL category to the Service/URL category tab on the security policy rule.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 19:00:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122162#M46110</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-10-28T19:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rule too allow access to group of URLs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122164#M46111</link>
      <description>&lt;P&gt;I think what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz﻿&lt;/a&gt;&amp;nbsp;is saying is that additonal traffic would hit this rule and match until it actually did the URL check. You would then need to have a rule after this one that would allow your other traffic to actually work, otherwise it would drop into the default 'deny' rule and your traffic would drop off.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 19:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-too-allow-access-to-group-of-urls/m-p/122164#M46111</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-10-28T19:26:21Z</dc:date>
    </item>
  </channel>
</rss>

