<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL filtering in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166420#M53332</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Depending on why the URL is needing to be blocked then yes. Generally though I would say that you should configure controllable EBLs, one for IP addresses and one for URLs, and then set them to auto-update at a resonable rate. This allows you to quickly deal with any issues like this and you don't really have to worry about them potentially not being on an EBL that you don't control.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jul 2017 22:38:05 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-07-13T22:38:05Z</dc:date>
    <item>
      <title>URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166352#M53311</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is there anyway to add a URL filtering for an individual &amp;nbsp;address?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 16:47:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166352#M53311</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-13T16:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166365#M53312</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You could always create a custom security policy for that address and assign the URL Filtering profile directly to that one profile. Would that work for what you are trying to do?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 17:07:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166365#M53312</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-13T17:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166370#M53314</link>
      <description>&lt;P&gt;Agree, URL filtering profiles per policy basis not per ip. One profile (or group) per policy. Get a separate policy&amp;nbsp;as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;has already mentioned&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 17:21:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166370#M53314</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-13T17:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166384#M53317</link>
      <description>&lt;P&gt;okay so I make a url filtering profile for one single web address that we want to block and then create a security policy with that profile in it. &amp;nbsp;&lt;/P&gt;&lt;P&gt;So if I can do this what does the url filtering subscription get you, we currently do no have it&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 18:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166384#M53317</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-13T18:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166385#M53318</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;- forgot to tag you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;okay so I make a url filtering profile for one single web address that we want to block and then create a security policy with that profile in it. &amp;nbsp;&lt;/P&gt;&lt;P&gt;So if I can do this what does the url filtering subscription get you, we currently do no have it&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 19:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166385#M53318</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-13T19:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166386#M53319</link>
      <description>&lt;P&gt;If you only want to log the accessed url's, allow only specific url's for example to a dmz server or as in your case you only need to block one (ore more) specific address(es) --&amp;gt; ther is no need for the url subscription&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the url subscription you can apply actions based on url categories. Here a few examples:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Block malware, phishing, peer2peer, dyn-dns, unknown&lt;/LI&gt;&lt;LI&gt;If your company policy does not allow social media&lt;/LI&gt;&lt;LI&gt;Allow downloads on all websites exept risky categories&lt;/LI&gt;&lt;LI&gt;With PAN-OS 8: allow your users to enter credentials on benign websites but not on unknown&lt;/LI&gt;&lt;LI&gt;...&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The list with possibilities is nearly endless &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But the main point is, that the subscription is for these categories and this is a point which you definately cannot do by yourself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Of course there are also other possibilities for "url filtering" for example DNS based, but this never gives you the control as you have it with actual http based url filtering)&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 19:15:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166386#M53319</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-07-13T19:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166387#M53320</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But you know it might get very burdomson to manage if I start trying manually add url's, people may request them to be blocked frequently&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 19:26:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166387#M53320</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-13T19:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166398#M53321</link>
      <description>&lt;P&gt;With EDLs this task is pretty easy to manage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And for websites in the wrong category our users simply have to wait until PaloAlto moves them to the right category (this process is at least much faster than with brightcloud) ... there still will be urgent requests but we did not have much of them in the past&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 19:45:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166398#M53321</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-07-13T19:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166401#M53323</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;when you are talking about EDL - External dynamic lists correct you mean ,list like MISP, emerging threat etc&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 20:13:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166401#M53323</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-13T20:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166408#M53325</link>
      <description>&lt;P&gt;Exactly I meant external dynamic lists ... such a list you can also use for the allow/block request from your users. Simply place it on an internal webserver where you can edit the file easily (with ftps, scp, smb) and a few minutes later (depending on how often you configure the sync) the website is allowed/blocked ondm your or (this is an even greater advantage) on all the firewalls you manage&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 20:37:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166408#M53325</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-07-13T20:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166412#M53328</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes we have two or three of &amp;nbsp;them and are using them as you and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;have suggested but I got a request to create a block for a specific URL that he couldn't find in one of the EDL lists that we have. It is possible of the other lists may have that url is there anyway to check on the PA&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 21:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166412#M53328</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-13T21:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166415#M53329</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Sure run the following in the CLI after you have modified it to match what you are looking for;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;'request system external-list show type&amp;nbsp;&lt;EM&gt;url&lt;/EM&gt;&amp;nbsp;name&amp;nbsp;&lt;EM&gt;name&lt;/EM&gt;'&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can then check against your EDLs easy enough. Sadly I don't believe there is a way to '| match' on this request. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 21:15:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166415#M53329</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-13T21:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166417#M53330</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Awesome I will check my other EDL lists&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what do you think about creating a rule/profile for just one URL&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 21:20:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166417#M53330</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-13T21:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166420#M53332</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Depending on why the URL is needing to be blocked then yes. Generally though I would say that you should configure controllable EBLs, one for IP addresses and one for URLs, and then set them to auto-update at a resonable rate. This allows you to quickly deal with any issues like this and you don't really have to worry about them potentially not being on an EBL that you don't control.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 22:38:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166420#M53332</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-13T22:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166531#M53349</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have had those kinds of lists set up for quite awhile but one of my coworker got an alert from bitsight about this URL&lt;/P&gt;&lt;P&gt;With this IP address 195.38.137.100and URL update.newinfoclientstack.com &amp;nbsp;that is not in any of the EDL list that we currently have set up and asked if I could create a block list for that specific IP address. My first thought is that if I do it once I will start get a lot of requests for individual addresses. So I was looking for away to avoid that&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 14 Jul 2017 13:15:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering/m-p/166531#M53349</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-14T13:15:12Z</dc:date>
    </item>
  </channel>
</rss>

