<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom URL Category in security rule - traffic log shows allowed with &amp;quot;any&amp;quot; in URL Cat in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/172249#M54374</link>
    <description>&lt;P&gt;Sorry for the delay in responding but I've been tied up with other things.&lt;BR /&gt;Also I will not be able to work on this for the next week.&lt;BR /&gt;When I can get back to this I will look at some of the things you've mentioned.&lt;/P&gt;&lt;P&gt;However in regard to your comment:&lt;BR /&gt;"What is likely happening is that the firewall allows the TCP/80 traffic, even identifies it as web-browsing, and then it attempts to match that traffic with your permit rules.&amp;nbsp; If it matches, great.&amp;nbsp; If not, it stops.&amp;nbsp; The trick question is, how should the firewall log the traffic?&amp;nbsp; Should it log the traffic as being denied (when some portion went through?)"&lt;/P&gt;&lt;P&gt;I would think that if the firewall is going to log this traffic as allowed because it got part way through the process, it should also have a denied entry when it determines that something about the rule (in my case the URL Category) prevents it.&amp;nbsp; It seems like this isn't happening and maybe that's just the way it works, however I find this confusing.&lt;/P&gt;&lt;P&gt;Thanks very much for your insight.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Aug 2017 17:54:30 GMT</pubDate>
    <dc:creator>herrmoss</dc:creator>
    <dc:date>2017-08-18T17:54:30Z</dc:date>
    <item>
      <title>Custom URL Category in security rule - traffic log shows allowed with "any" in URL Category field</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171886#M54299</link>
      <description>&lt;P&gt;I've read the articles about the processes that take place when analyzing traffic and understand that sometimes there could be an allow status when it seems there shouldn't be.&amp;nbsp; However it also seems that if the traffic truly shouldn't be allowed there would be an associated log entry with some kind of denial.&lt;BR /&gt;In my case there is no associated denial and I'm would still like to know why this traffic seems to be allowed when apparently not matching my Custom URL Category.&lt;BR /&gt;Forgive me if I'm still just misunderstanding something about this.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Here's what I'm seeing in my logs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UrlCat.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10809i5E2A0FD26E570348/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="UrlCat.jpg" alt="UrlCat.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 15:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171886#M54299</guid>
      <dc:creator>herrmoss</dc:creator>
      <dc:date>2017-08-16T15:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171894#M54300</link>
      <description>&lt;P&gt;What if you also create a URL Filtering Profile (call it Alert All URL), configured with "alert" for all categories, and attach it to this rule?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 15:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171894#M54300</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-08-16T15:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171904#M54302</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15981"&gt;@herrmoss&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because of the any I think the reason is one of the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You did not attach the custom URL category to the policy&lt;/LI&gt;&lt;LI&gt;Traffic hits a rule before your rule with the attached custom URL category&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you share some more screenshots (logs with column 'rule', security policy in question, custom URL category), we should be able to help &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 16:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171904#M54302</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-16T16:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171924#M54307</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Unfortunately we don't have a URL Filtering license as we have another solution for that function.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 18:12:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171924#M54307</guid>
      <dc:creator>herrmoss</dc:creator>
      <dc:date>2017-08-16T18:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171932#M54309</link>
      <description>&lt;P&gt;For that what you intended to do (at least what I understood) - blocking or allowing specific websites with a custom URL category directly referenced in the security policy, you don't need an URL filtering license. Even for the logging part, mentionned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;, there are workarounds that you will see the URL logs, without the license (only a workaround, not a recommended way)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 18:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171932#M54309</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-16T18:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171959#M54316</link>
      <description>&lt;P&gt;You are correct&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;I only mentioned the licensing issue becuase &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;&amp;nbsp;mentioned creating a URL Filtering Profile and I believe I can't do that without a license.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 20:31:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171959#M54316</guid>
      <dc:creator>herrmoss</dc:creator>
      <dc:date>2017-08-16T20:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171963#M54317</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;attaching more screenshots.&lt;/P&gt;&lt;P&gt;And to be clear, the Custom URL Category is showing up for most of the log entries, I'm just confused about why it's not showing up for some.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Logs.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10817iFB84991F5B0BB75E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Logs.jpg" alt="Logs.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10816iC4DE492CBD2EF8DE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule.jpg" alt="rule.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="URL_Cat.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10815i42C3BFD985AFB3EF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="URL_Cat.jpg" alt="URL_Cat.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 20:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171963#M54317</guid>
      <dc:creator>herrmoss</dc:creator>
      <dc:date>2017-08-16T20:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171964#M54318</link>
      <description>&lt;P&gt;I just tried with an unlicensed lab firewall. &amp;nbsp;I was able to create a URL filtering profile, configure it to alert on my custom categories, add the URL filtering profile to a security policy, and commit the changes. &amp;nbsp;There is a commit warning complaining about no URL license, but it's a successful commit. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The colum that says "any" is only populated by attaching a URL filtering profile. &amp;nbsp;I'm guessing this is why you're not seeing anything in that column. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go ahead and create a URL filtering profile w/ "alert" as the action for all categories (or alert on your custom categories, and allow on all the rest), and attach it to your security policy. &amp;nbsp;Commit and test. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 20:45:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171964#M54318</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-08-16T20:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171967#M54319</link>
      <description>&lt;P&gt;I didn't realize that you could create a URL Filtering profile without a license.&amp;nbsp; Not sure I would like getting that warning (I assume I would continue to get this on subsequent commits).&lt;/P&gt;&lt;P&gt;Again, just to be clear, I do get my URL Category showing up in the logs (I just filtered those out in my previous images).&amp;nbsp; Here's another look at the logs without the filtering and an example of "any" circled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, my main goal here is to be able to confidentally tell upper management that no traffic is being allowed to a destination that is not in my URL Category.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LogNoFilter.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10818i573AA253531662F0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LogNoFilter.jpg" alt="LogNoFilter.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 21:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171967#M54319</guid>
      <dc:creator>herrmoss</dc:creator>
      <dc:date>2017-08-16T21:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171978#M54325</link>
      <description>&lt;P&gt;Understanding your main goal is helpful. &amp;nbsp;Looking at your security policy, I don't see all of the applications you're allowing. &amp;nbsp;Since SSL is in the list, I'm assuming web-browsing is in the list too. &amp;nbsp;If it is, then this may be happening:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client PC sends SYN on TCP/80, firewall doesn't know what the application is yet, but since you have a rule that allows web-browsing on TCP/80, that packet is permitted to pass. &amp;nbsp;At this point the firewall doesn't know what the application is, let alone the URL. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Server responds with SYN/ACK. &amp;nbsp;At this point, firewall still doesn't know what the application is yet, but since there are rules that allow web-browsing on TCP/80, firewall will continue to permit the handshake and subsequent data packets until it can definitively match your policies. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client responds with ACK. &amp;nbsp;Firewall still doesn't know application or URL. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client sends some request on TCP/80. &amp;nbsp;This is the firewall's first opportunity to look at layer-7 data and start determining things like application and URL. &amp;nbsp;Some applications are immediately recognizeable and the firewall can take action beginning with this packet. &amp;nbsp;Other applications require a couple of packets in order to definitively identify the application. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is likely happening is that the firewall allows the TCP/80 traffic, even identifies it as web-browsing, and then it attempts to match that traffic with your permit rules. &amp;nbsp;If it matches, great. &amp;nbsp;If not, it stops. &amp;nbsp;The trick question is, how should the firewall log the traffic? &amp;nbsp;Should it log the traffic as being denied (when some portion went through?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you add the packets sent / packets received columns to your log view? &amp;nbsp;That would be an interesting datapoint for the traffic that you've circled. &amp;nbsp;Also add the "Session ID" column. &amp;nbsp;From the CLI run a "show session id xxxxxxxx" for the traffic log and see what additional detail is available. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would also be helpful to know the exact URL that generated this traffic log. &amp;nbsp;I seem to remember a way to do this. &amp;nbsp;It involves creating a URL Filtering Profile...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: &amp;nbsp;I'd recommend reading up on application dependencies, as this may be part of the issue. &amp;nbsp;Also, this (&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Blocked-traffic-has-an-allow-log/ta-p/72357" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Blocked-traffic-has-an-allow-log/ta-p/72357&lt;/A&gt;) is another possibility.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 22:03:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/171978#M54325</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-08-16T22:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/172012#M54333</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;It is possible to configure the url profile without a license and apply it to a policy ... but did yoz really get url logs?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 06:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/172012#M54333</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-17T06:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/172249#M54374</link>
      <description>&lt;P&gt;Sorry for the delay in responding but I've been tied up with other things.&lt;BR /&gt;Also I will not be able to work on this for the next week.&lt;BR /&gt;When I can get back to this I will look at some of the things you've mentioned.&lt;/P&gt;&lt;P&gt;However in regard to your comment:&lt;BR /&gt;"What is likely happening is that the firewall allows the TCP/80 traffic, even identifies it as web-browsing, and then it attempts to match that traffic with your permit rules.&amp;nbsp; If it matches, great.&amp;nbsp; If not, it stops.&amp;nbsp; The trick question is, how should the firewall log the traffic?&amp;nbsp; Should it log the traffic as being denied (when some portion went through?)"&lt;/P&gt;&lt;P&gt;I would think that if the firewall is going to log this traffic as allowed because it got part way through the process, it should also have a denied entry when it determines that something about the rule (in my case the URL Category) prevents it.&amp;nbsp; It seems like this isn't happening and maybe that's just the way it works, however I find this confusing.&lt;/P&gt;&lt;P&gt;Thanks very much for your insight.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2017 17:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/172249#M54374</guid>
      <dc:creator>herrmoss</dc:creator>
      <dc:date>2017-08-18T17:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category in security rule - traffic log shows allowed with "any" in URL Cat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/175971#M55079</link>
      <description>&lt;P&gt;So &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;, in betwen my other priorities I have been researching this issue with my limited knowledge and understanding.&lt;/P&gt;&lt;P&gt;I have discovered that in 60% of the cases the destination IP Address allowed&amp;nbsp;that shows "any" for URL Category in the logs has been also been allowed&amp;nbsp;sometimes with the correct URL Category showing.&amp;nbsp; I'm not sure why this is and am at a loss to explain the remaining 40% that never show the correct URL Category.&lt;/P&gt;&lt;P&gt;At this point I am willing to accept this behavior but will continue to monitor.&lt;/P&gt;&lt;P&gt;Thanks for your time on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2017 17:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-in-security-rule-traffic-log-shows-allowed/m-p/175971#M55079</guid>
      <dc:creator>herrmoss</dc:creator>
      <dc:date>2017-09-11T17:33:23Z</dc:date>
    </item>
  </channel>
</rss>

