<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Source Based Custom URL Lists in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/133807#M47263</link>
    <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know a way to setup source-based Custom URL Lists containing domains as an alternative to using source-based IP addresses and address groups? &amp;nbsp;I don't think it's possible in any of the current versions of PAN-OS but i am looking at options.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;For example, if i want to limit inbound SMTP to our edge Exchange server from the Microsoft Exchange Online cloud, I have to add 24 IP addresses that resolve to &lt;EM&gt;*.outbound.protection.outlook.com&lt;/EM&gt;. &amp;nbsp;It would be a way better solution to just allow IP's that all resolve to a&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;*.outbound.protection.&lt;/EM&gt;&lt;/SPAN&gt;&lt;EM&gt;outlook.&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;com&lt;/EM&gt;&amp;nbsp;contained in a Custom URL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am I just missing something here? &amp;nbsp;Is there a better way to do this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Dec 2016 20:18:02 GMT</pubDate>
    <dc:creator>mlinsemier</dc:creator>
    <dc:date>2016-12-20T20:18:02Z</dc:date>
    <item>
      <title>Source Based Custom URL Lists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/133807#M47263</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know a way to setup source-based Custom URL Lists containing domains as an alternative to using source-based IP addresses and address groups? &amp;nbsp;I don't think it's possible in any of the current versions of PAN-OS but i am looking at options.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;For example, if i want to limit inbound SMTP to our edge Exchange server from the Microsoft Exchange Online cloud, I have to add 24 IP addresses that resolve to &lt;EM&gt;*.outbound.protection.outlook.com&lt;/EM&gt;. &amp;nbsp;It would be a way better solution to just allow IP's that all resolve to a&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;*.outbound.protection.&lt;/EM&gt;&lt;/SPAN&gt;&lt;EM&gt;outlook.&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;com&lt;/EM&gt;&amp;nbsp;contained in a Custom URL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am I just missing something here? &amp;nbsp;Is there a better way to do this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 20:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/133807#M47263</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2016-12-20T20:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Source Based Custom URL Lists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/133869#M47268</link>
      <description>&lt;P&gt;URL categories can be used for web-browsing traffic not SMTP.&lt;/P&gt;&lt;P&gt;For other traffic you can use IP's or address objects. Address object can be FQDN so name.&lt;/P&gt;&lt;P&gt;&lt;A title="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-and-Test-FQDN-Objects/ta-p/61903" href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-and-Test-FQDN-Objects/ta-p/61903" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-and-Test-FQDN-Objects/ta-p/61903&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Most likely this will not resolve your wish to match *. addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto has tool MimeMeld &amp;nbsp;( &lt;A title="https://live.paloaltonetworks.com/t5/MineMeld/ct-p/MineMeld" href="https://live.paloaltonetworks.com/t5/MineMeld/ct-p/MineMeld" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld/ct-p/MineMeld&lt;/A&gt;&amp;nbsp;) that can pull info from diferent sources (for example MS IP list&amp;nbsp;&lt;A title="https://support.content.office.net/en-us/static/O365IPAddresses.xml" href="https://support.content.office.net/en-us/static/O365IPAddresses.xml" target="_blank"&gt;https://support.content.office.net/en-us/static/O365IPAddresses.xml&lt;/A&gt;&amp;nbsp;) and Palo can pull this info from MimeMeld and you can use this data in source ip address field of your policy.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 04:33:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/133869#M47268</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-12-21T04:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Source Based Custom URL Lists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/134059#M47300</link>
      <description>&lt;P&gt;This offers some clarity to URL categories as I was always curious on web-browsing/ssl traffic or say a protocol like SMTP using TLS1 (ssl). &amp;nbsp;This actually make much more sense now going forward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are right by saying using FQDN will not work as I cannot use *.domain.com in it which is what really i want to be able to do. &amp;nbsp;Ulitimately i ended up adding the 24 host subnets&amp;nbsp;which resolves the issue, but being able to do wildcard source domains would be way cleaner as unless the domain and subdomains change completely, you would never have to update a IP list again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will take a look at the MineMeld tool as well. &amp;nbsp;I wanted to look at this in the past, I just ran out of cycles to do so. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for this!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 18:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/134059#M47300</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2016-12-21T18:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Source Based Custom URL Lists</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/134060#M47301</link>
      <description>&lt;P&gt;Few more bits.&lt;/P&gt;&lt;P&gt;URL category is compared to HTTP GET request field.&lt;/P&gt;&lt;P&gt;If you don't decrypt SSL/TLS then this flies by in encrypted payload and Palo can only read data on certificate and compare this to URL category.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FQDN resolves name to IP's (like if you run nslookup &lt;A href="http://www.microsoft.com" target="_blank"&gt;www.microsoft.com&lt;/A&gt; from command prompt) and it is impossible to resolve *.microsoft.com against dns server.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 18:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-based-custom-url-lists/m-p/134060#M47301</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-12-21T18:41:31Z</dc:date>
    </item>
  </channel>
</rss>

