<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PAN 6.1: Filtering inbound traffic layer 7 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-6-1-filtering-inbound-traffic-layer-7/m-p/143047#M48655</link>
    <description>&lt;P&gt;If I expose a server to the Internet, can I limit traffic at the PAN so that only a specific&amp;nbsp;path can be reached?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say permit &lt;A href="http://www.hoho.com/foo.html" target="_blank"&gt;www.hoho.com/foo.html&lt;/A&gt; but deny &lt;A href="http://www.hoho.com/fa.html" target="_blank"&gt;www.hoho.com/fa.html&lt;/A&gt; or any other path?&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2017 00:06:22 GMT</pubDate>
    <dc:creator>palomed</dc:creator>
    <dc:date>2017-02-15T00:06:22Z</dc:date>
    <item>
      <title>PAN 6.1: Filtering inbound traffic layer 7</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-6-1-filtering-inbound-traffic-layer-7/m-p/143047#M48655</link>
      <description>&lt;P&gt;If I expose a server to the Internet, can I limit traffic at the PAN so that only a specific&amp;nbsp;path can be reached?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say permit &lt;A href="http://www.hoho.com/foo.html" target="_blank"&gt;www.hoho.com/foo.html&lt;/A&gt; but deny &lt;A href="http://www.hoho.com/fa.html" target="_blank"&gt;www.hoho.com/fa.html&lt;/A&gt; or any other path?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 00:06:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-6-1-filtering-inbound-traffic-layer-7/m-p/143047#M48655</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-02-15T00:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: PAN 6.1: Filtering inbound traffic layer 7</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-6-1-filtering-inbound-traffic-layer-7/m-p/143070#M48656</link>
      <description>&lt;P&gt;You could use a custom IPS signature that resets connection for traffic that matches the following conditions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;- host = &lt;A href="http://www.hoho.com" target="_blank"&gt;www.hoho.com&lt;/A&gt; or hoho.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;- uri/path does NOT = foo.html (or does not contain foo.html, or does not equal to /path1/path2/foo.html, etc.)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matching against &lt;A href="http://www.hoho.com" target="_blank"&gt;www.hoho.com&lt;/A&gt; and/or hoho.com will effectively "arm" the signature, and as if the path strays from what is allowed, it will fire, resetting the connection. &amp;nbsp;If the path matches what is allowed, then the connection will be allowed to flow normally.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could use a custom AppID signature instead. &amp;nbsp;The logic would be the same, but the policy would look different. &amp;nbsp;Instead of "permit web-browsing to webserver with "custom IPS signature" enabled", it would be "permit application=hoho-com to webserver"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly not sure which one would be better... I'd recommend trying them both out to see which one more fully meets your needs. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this server provide SSL or just HTTP? &amp;nbsp;If it's SSL, you'll also need to use an Inbound SSL Inspection profile so that the firewall can look inside of SSL and validate the /foo.html part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Documentation for starting points:&lt;/P&gt;&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Creating-Custom-Threat-Signatures/ta-p/58569" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Creating-Custom-Threat-Signatures/ta-p/58569&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Custom-Application-Signatures/ta-p/58625" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Custom-Application-Signatures/ta-p/58625&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 03:24:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-6-1-filtering-inbound-traffic-layer-7/m-p/143070#M48656</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-02-15T03:24:19Z</dc:date>
    </item>
  </channel>
</rss>

