<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: url filtering question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154730#M50942</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a possiblity &amp;nbsp;giving certificate error instead of giving &amp;nbsp;response page (from palo alto ) &amp;nbsp;to the&amp;nbsp;&lt;/P&gt;&lt;P&gt;End user&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 May 2017 18:14:44 GMT</pubDate>
    <dc:creator>simsim</dc:creator>
    <dc:date>2017-05-01T18:14:44Z</dc:date>
    <item>
      <title>url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154718#M50938</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How PA &amp;nbsp;categorize (business or &amp;nbsp;research....) and filter if a proxy server re writing a url .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for example&amp;nbsp;&lt;/P&gt;&lt;P&gt;if the original url is &lt;SPAN&gt;https://&lt;/SPAN&gt;yyyy.com &amp;nbsp;and after rewriting &amp;nbsp;it became &lt;SPAN&gt;https://&lt;/SPAN&gt;&lt;SPAN&gt;yyyy.com.proxy.mycompany.com&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a possiblity &amp;nbsp;giving certificate error instead of giving &amp;nbsp;access deined &amp;nbsp; message (from palo alto &amp;nbsp;by url filtering) &amp;nbsp; to the&amp;nbsp;&lt;/P&gt;&lt;P&gt;End user&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 17:29:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154718#M50938</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-01T17:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154728#M50941</link>
      <description>&lt;P&gt;Most likely it will be categorized as "unknown"&lt;/P&gt;&lt;P&gt;If you block unknown category those sites will be blocked.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 17:48:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154728#M50941</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-01T17:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154730#M50942</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a possiblity &amp;nbsp;giving certificate error instead of giving &amp;nbsp;response page (from palo alto ) &amp;nbsp;to the&amp;nbsp;&lt;/P&gt;&lt;P&gt;End user&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 18:14:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154730#M50942</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-01T18:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154737#M50943</link>
      <description>&lt;P&gt;Initially I missed the part that it is https site.&lt;/P&gt;&lt;P&gt;Issue is that unless you decrypt traffic Palo does not see HTTP GET and it can identify only name on the certificate.&lt;/P&gt;&lt;P&gt;So if you don't decrypt https then https traffic might even be categorized correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you check your URL Filter log to identify what category this URL is assigned to and what action fields shows.&lt;/P&gt;&lt;P&gt;What response page tells to be reason why was this site blocked?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 18:38:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154737#M50943</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-01T18:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154741#M50945</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I can't find anything&amp;nbsp;in the log related with the url,&lt;/P&gt;&lt;P&gt;the user getting an error like below &amp;nbsp;, I was assumming &amp;nbsp;PA doing something ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel it like it happens after url filtering added in the policy .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificate seems to be ok .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is your expert opinion&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fb error.JPG" style="width: 652px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9012iD05383C6F030B96F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fb error.JPG" alt="fb error.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 19:29:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154741#M50945</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-01T19:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154743#M50946</link>
      <description>&lt;P&gt;If this just started happening then Chrome's 58 update broke a large amount of MitM decryption/proxying methods. I would assume that you should likely take a look at your proxy if this is the case, it's likely that Chrome simply doesn't like that your proxy is feeding unencrypted traffic for domains that should be encrypted hence the warning message stating that traffic from/to facebook is usually encrypted but now it is not.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 19:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154743#M50946</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-01T19:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154746#M50948</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It's not facebook , I just was showing the error . I am getting this error in firefox , chrome &amp;nbsp;(ver 57).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there something &amp;nbsp;needed to verified from PA side &amp;nbsp;finally as per your expert opinion&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here what I am getting on the firefox&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your connection is not private&lt;BR /&gt;Attackers might be trying to steal your information from&lt;STRONG&gt; yyyy.com.proxy.mycompany.com&lt;/STRONG&gt;&lt;BR /&gt;(for example, passwords, messages or credit cards).&lt;BR /&gt;net-err_cert_common_name_invalid&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hide Advanced&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This server could not prove that it is yyyy.com.proxy.mycompany.com ; its security certificate is from&lt;BR /&gt;&lt;STRONG&gt;*.proxy.mycompany.com.&lt;/STRONG&gt;&lt;BR /&gt;This may be caused by a misconfiguration or an attacker intercepting your connection.&lt;BR /&gt;Proceed to yyyy.com.proxy.mycompany.com (unsafe)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;proxy team blames PA : ) because of the sentence in the error message &amp;nbsp;&lt;STRONG&gt;"This may be caused by a misconfiguration or an attacker intercepting your connection."&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 19:52:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154746#M50948</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-01T19:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154748#M50950</link>
      <description>&lt;P&gt;You asked "&lt;SPAN&gt;Is there a possiblity &amp;nbsp;giving certificate error instead of giving &amp;nbsp;response page"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Well screenshot you posted is cert error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does this happen with every browser?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does cert match url?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is CA cert that SSL Proxy uses still valid or expired?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Find a site that resolves to single ip (not google or facebook).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Go to a site.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Close browser to end session.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Check traffic log towards this IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Click on mag glass to view session details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What URL category you see?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With URL filtering if action is "allow" then category is permitted but log is not written. If action is "alert" category is permitted and log is writted to URL Filtering log.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 20:24:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154748#M50950</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-01T20:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154752#M50951</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59972"&gt;@simsim&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So if I have this correct then the following is true.&lt;/P&gt;&lt;P&gt;1) You utilize a proxy server that is serperate from the Palo Alto deivce?&lt;/P&gt;&lt;P&gt;2) This was working and your Palo Alto is not a new install?&lt;/P&gt;&lt;P&gt;3) The after a set date 'just stopped' regardless of browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that's the case then it sounds like your certificate that is fed from traffic delivered by your proxy has expired or in some way for some reason no longer trusted by your client devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either the certificate just expired on your proxy, or the proxy server itself is new. I don't believe that the Palo Alto is really playing a part in this at all unless this is a brand new deployment.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 21:06:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154752#M50951</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-01T21:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154754#M50952</link>
      <description>&lt;P&gt;The answer is actually in the recent update:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Attackers might be trying to steal your information from&lt;STRONG&gt; yyyy.com.proxy.mycompany.com&lt;/STRONG&gt;&lt;BR /&gt;(for example, passwords, messages or credit cards).&lt;BR /&gt;net-err_cert_common_name_invalid&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hide Advanced&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This server could not prove that it is yyyy.com.proxy.mycompany.com ; its security certificate is from&lt;BR /&gt;&lt;STRONG&gt;*.proxy.mycompany.com.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The certificate on the proxy is wrong. Each "dot" is literal when it comes to wildcard certificates. If it's for *.example.com, but the URI requested is alpha.bravo.example.com, then it won't match. If you want to match on those, your cert would need to have a Subject Alternative Name field of at least:&lt;/P&gt;&lt;P&gt;*.example.com&lt;/P&gt;&lt;P&gt;*.*.example.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each subdomain level needs a separate *. for itself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason you're getting the HSTS message is that you had previously gone to the site in that browser and it pinned the certificate from before.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 21:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154754#M50952</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-05-01T21:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154758#M50953</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is the &amp;nbsp;vendor &amp;nbsp; requirement for wildcard .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is their defenition of &amp;nbsp;wildcard&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&lt;EM&gt;n the following, Regular refers to a certificate that is issued in the exact name of your EZproxy server (e.g., ezproxy.yourlib.org) whereas Wildcard refers to a certificate that is issued as *. followed by the exact name of your EZproxy server (e.g., *.ezproxy.yourlib.org). These form of certificate names are the two types that can be created from within the SSL configuration option provided by EZproxy.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;( we choose the above )&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If you create a wildcard certificate outside of EZproxy that is a wildcard for your domain (e.g., *.yourlib.org) and if you are using proxy by hostname, you must edit &lt;SPAN class="cq-rte-sprinkles"&gt;config.txt&lt;/SPAN&gt; and add "Option&amp;nbsp;IgnoreWildcardCertificate" to indicate that your wildcard is not in the form EZproxy expects. If you do this, your wildcard certificate will behave as a Regular certificate, which includes providing browser warnings when https web sites are proxied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note on wildcard certificates: EZproxy expects the wildcard domain name to be specified with the CN element in the Subject field.&amp;nbsp; The non-wildcard domain should be specified as a DNS element in the Subject Alternative Name (SAN) field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;yyyy.com.proxy.mycompany.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;here yyyy.com a site which reside outside &amp;nbsp;and proxy.mycompany.com is &amp;nbsp; proxy server fqdn&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 22:40:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154758#M50953</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-01T22:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154759#M50954</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;1) You utilize a proxy server that is serperate from the Palo Alto deivce?&lt;/P&gt;&lt;P&gt;yes&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) This was working and your Palo Alto is not a new install?&lt;/P&gt;&lt;P&gt;yes&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3) The after a set date 'just stopped' regardless of browser.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;let's say two persons are using same chrome or firefox ,for one person it works, the other one it does not .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And IE users almost it 's ok&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 22:30:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-question/m-p/154759#M50954</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-01T22:30:32Z</dc:date>
    </item>
  </channel>
</rss>

