<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom URL Category in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169895#M53934</link>
    <description>&lt;P&gt;If you don't decrypt traffic then HTTP GET goes inside encrypted payload and Palo identifies site based on name on the certificate. So check what name cert has on it.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2017 17:39:09 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2017-08-03T17:39:09Z</dc:date>
    <item>
      <title>Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169881#M53933</link>
      <description>&lt;P&gt;I have a test url category with only one url. i have applied this url category to a test policy, not using a profile but directly in the policy under "service/url category".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i browse to the site it uses the correct policy to allow the request...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;however... any other traffic that cannot be decrypted is showing in the traffic logs as url category "Any" and this is also allowed via my test policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;am i missing something here?.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mick.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 16:53:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169881#M53933</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-08-03T16:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169895#M53934</link>
      <description>&lt;P&gt;If you don't decrypt traffic then HTTP GET goes inside encrypted payload and Palo identifies site based on name on the certificate. So check what name cert has on it.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 17:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169895#M53934</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-08-03T17:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169897#M53936</link>
      <description>&lt;P&gt;Raido, thanks for your reply. I was aware of non decrypted procedure on palo and can assure you that the cert name of these sites does not match the url in the custom category.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i cannot understand why firstly these allowed sites are catagorised as "url category ANY" and secondly why they are allowed through the policy where the url cat is "test" not "any".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mick.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 17:53:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169897#M53936</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-08-03T17:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169912#M53941</link>
      <description>&lt;P&gt;Additional information: rhe firewall does know the exact fqdn (in almost every case), because in the TLS hanshake there is the SNI attribute where the fqdn is sent in cleartext.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 18:31:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169912#M53941</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-03T18:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169919#M53942</link>
      <description>&lt;P&gt;Check your traffic log to see if there's any actual bi-directional traffic hitting it. If there are only a few packets, it's not actually matching that policy in a real way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When a TCP connection first starts out, the 3-way handshake can't have the concept of a URL category so that much is allowed on your test rule as it&amp;nbsp;&lt;STRONG&gt;could&lt;/STRONG&gt; belong to that custom category. Once the Client Hello (or whatever else the traffic is, like an HTTP GET or some other protocol entirely), then the firewall has enough information to know it doesn't belong to that custom category, marking the session as Discard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the initial packets were allowed via your test rule, the firewall logs that as the rule.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 18:36:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169919#M53942</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-08-03T18:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169920#M53943</link>
      <description>&lt;P&gt;Gwesson, wow... Thanks.... Good point. I will check in the morning and update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mick.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 18:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/169920#M53943</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-08-03T18:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/170033#M53968</link>
      <description>&lt;P&gt;Gwesson, thankyou for your time and explanation. you are correct in your explanation. I changed the logging to "session end" and now see no traffic passing through the test policy (of course it actually still is but only for the reason that you explained earlier).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't thank you enough.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mick.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 09:07:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/170033#M53968</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-08-04T09:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/260551#M73855</link>
      <description>&lt;P&gt;Does this URL category (URL column and URL Profile) match initially on other rules as well, say for instance if you have a couple of rules that allow ssl/web browsing, and are being decrypted, and one has custom URL category column, and one has simply a profile?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 18:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/260551#M73855</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-05-10T18:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/260618#M73872</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59122"&gt;@Sec101&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic will always match only one rule. Even if there could be multiple matches, the first rule that matches will be applied. Only adding the URL category directly into the rule is a matching criteria, not the URL profile.&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2019 18:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/260618#M73872</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-11T18:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/260619#M73873</link>
      <description>&lt;P&gt;Great explanation!&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2019 19:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category/m-p/260619#M73873</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-11T19:17:18Z</dc:date>
    </item>
  </channel>
</rss>

