<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom URL matching on wrong URLs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202802#M59807</link>
    <description>&lt;P&gt;Wow, I don't know what's going on here with the pictures.&amp;nbsp; I see them after posting, but then a few minutes later they don't show up.&amp;nbsp; Let's try it via links instead of embedded photos.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security Rule: &lt;A href="http://www.harmelin.com/Palo/secrule.png" target="_blank"&gt;http://www.harmelin.com/Palo/secrule.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;URL Category: &lt;A href="http://www.harmelin.com/Palo/urlcat.png" target="_blank"&gt;http://www.harmelin.com/Palo/urlcat.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Log: &lt;A href="http://www.harmelin.com/Palo/log.png" target="_blank"&gt;http://www.harmelin.com/Palo/log.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2018 15:18:58 GMT</pubDate>
    <dc:creator>mprintz</dc:creator>
    <dc:date>2018-02-28T15:18:58Z</dc:date>
    <item>
      <title>Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202619#M59762</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a security rule that's supposed to be only allowing traffic for URLs in a custom URL category. &amp;nbsp;However, it appears that it's matching lots of other URLs that aren't in the category. &amp;nbsp;Below are some screenshots. &amp;nbsp;I'm running v8.0.6. &amp;nbsp;Let me know what other info you might need and what I'm doing wrong. &amp;nbsp;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security rule showing URL category specified:&lt;/P&gt;&lt;P&gt;&lt;IMG src="blob:https://live.paloaltonetworks.com/75116c4d-1714-4111-85e7-cc245131afba" border="0" width="914" height="83" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Custom URL category:&lt;/P&gt;&lt;P&gt;&lt;IMG src="blob:https://live.paloaltonetworks.com/deb45727-adfa-4f81-9b48-d9ee7f2e518e" border="0" width="438" height="278" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unified log showing other URLs not listed above matching security rule (e.g. first and last lines):&lt;/P&gt;&lt;P&gt;&lt;IMG src="blob:https://live.paloaltonetworks.com/51170a31-feff-4cb3-bb43-697dbd03e646" border="0" width="1035" height="218" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 21:13:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202619#M59762</guid>
      <dc:creator>mprintz</dc:creator>
      <dc:date>2018-02-27T21:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202692#M59772</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38489"&gt;@mprintz&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe something went wrong when uploading the screenshots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 08:14:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202692#M59772</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-02-28T08:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202740#M59782</link>
      <description>&lt;P&gt;Sorry about that, not sure what happened. &amp;nbsp;I could even see them when I did the preview. &amp;nbsp;Let's try again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security rule:&lt;/P&gt;&lt;P&gt;&lt;IMG src="blob:https://live.paloaltonetworks.com/19b3b49f-a054-4ed4-bf1d-2b3a80f44e1e" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Custom URL category:&lt;/P&gt;&lt;P&gt;&lt;IMG src="blob:https://live.paloaltonetworks.com/6add4410-b081-4aa7-b1bd-8c3eb8641fd8" border="0" width="462" height="299" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log - in this case, lines 3, 6, &amp;amp; 11 showing the mismatched URLs:&lt;/P&gt;&lt;P&gt;&lt;IMG src="blob:https://live.paloaltonetworks.com/80bd6a47-adad-47ea-893d-514ef10b759e" border="0" width="864" height="232" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 13:36:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202740#M59782</guid>
      <dc:creator>mprintz</dc:creator>
      <dc:date>2018-02-28T13:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202791#M59801</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm not able to see the images.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 15:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202791#M59801</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-28T15:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202802#M59807</link>
      <description>&lt;P&gt;Wow, I don't know what's going on here with the pictures.&amp;nbsp; I see them after posting, but then a few minutes later they don't show up.&amp;nbsp; Let's try it via links instead of embedded photos.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security Rule: &lt;A href="http://www.harmelin.com/Palo/secrule.png" target="_blank"&gt;http://www.harmelin.com/Palo/secrule.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;URL Category: &lt;A href="http://www.harmelin.com/Palo/urlcat.png" target="_blank"&gt;http://www.harmelin.com/Palo/urlcat.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Log: &lt;A href="http://www.harmelin.com/Palo/log.png" target="_blank"&gt;http://www.harmelin.com/Palo/log.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 15:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202802#M59807</guid>
      <dc:creator>mprintz</dc:creator>
      <dc:date>2018-02-28T15:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202837#M59820</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38489"&gt;@mprintz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is usually caused because you've allowed akamai.net as a URL. You only actually need to allow the following.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://windowsupdate.microsoft.com" target="_blank"&gt;http://windowsupdate.microsoft.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;http://*.windowsupdate.microsoft.com&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;https://*.windowsupdate.microsoft.com&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;http://*.update.microsoft.com&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;https://*.update.microsoft.com&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;http://*.windowsupdate.com&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://download.windowsupdate.com" target="_blank"&gt;http://download.windowsupdate.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://download.microsoft.com" target="_blank"&gt;http://download.microsoft.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;http://*.download.windowsupdate.com&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://test.stats.update.microsoft.com" target="_blank"&gt;http://test.stats.update.microsoft.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://ntservicepack.microsoft.com" target="_blank"&gt;http://ntservicepack.microsoft.com&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Feb 2018 17:52:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202837#M59820</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-28T17:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202868#M59825</link>
      <description>&lt;P&gt;As BPry said above, the 2 bottom IPs are probably going through something hosted by akamai. I see them listed as zscaler, they might be a cloud platform hosted on akamai.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://technet.microsoft.com/en-us/library/bb693717.aspx" target="_blank"&gt;https://technet.microsoft.com/en-us/library/bb693717.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Same list as above&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 19:15:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202868#M59825</guid>
      <dc:creator>Rags</dc:creator>
      <dc:date>2018-02-28T19:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202873#M59827</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/943"&gt;@Rags&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Funny enough while ZScaler is a competitor of some of the features that Akamai provides; they actually utilize akamai for ZEN lookup.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 19:25:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202873#M59827</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-28T19:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202887#M59837</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38489"&gt;@mprintz&lt;/a&gt;&lt;/P&gt;&lt;P&gt;As proposed by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/943"&gt;@Rags&lt;/a&gt;&amp;nbsp;you should change the url category.&lt;/P&gt;&lt;P&gt;But did you also filter for the destination IPs of these 2 log entries. As this log shows a threat log entry with the subtype spyware these entries don't necessarily mean that this traffic was allowed - 3 log entries aren't enough to say that for sure. It could be that the antispyware feature logged this but after that the traffic was blocked because of the url not matching your custom url category.&lt;/P&gt;&lt;P&gt;(Do you log the theat for TLS evasions? Are these 2 entries such threats?)&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 21:00:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202887#M59837</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-28T21:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202889#M59839</link>
      <description>&lt;P&gt;I changed the Custom URL Category so that it only contains the URLs below, but I'm still seeing all sorts of other URLs in the logs (&lt;A href="http://www.harmelin.com/Palo/log2.png" target="_blank"&gt;http://www.harmelin.com/Palo/log2.png&lt;/A&gt;). &amp;nbsp;Any other ideas? &amp;nbsp;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;We are using Zscaler, so it would make sense that some of the traffic would have been hitting that rule before, if it was destined for akamai and Zscaler&amp;nbsp;uses their service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*.update.microsoft.com&lt;/P&gt;&lt;P&gt;*.windowsupdate.com&lt;/P&gt;&lt;P&gt;*.windowsupdate.microsoft.com&lt;/P&gt;&lt;P&gt;download.microsoft.com&lt;/P&gt;&lt;P&gt;ntservicepack.microsoft.com&lt;/P&gt;&lt;P&gt;windowsupdate.microsoft.com&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 21:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202889#M59839</guid>
      <dc:creator>mprintz</dc:creator>
      <dc:date>2018-02-28T21:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202890#M59840</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38489"&gt;@mprintz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you decrypting traffic at all or not?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 21:21:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202890#M59840</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-28T21:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202898#M59842</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Yes, I am for that URL category and a handful of other URLs (none of the ones in the logs I've posted), as well as some non-HTTP services. &amp;nbsp;However, that's a recent change I made to see if it would fix the problem, but it didn't.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 21:29:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202898#M59842</guid>
      <dc:creator>mprintz</dc:creator>
      <dc:date>2018-02-28T21:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202899#M59843</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38489"&gt;@mprintz&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you actually have in this screenshot are connection attempts. In the screenshot there are no urls in the URL column in the monitor tab, so the firewall was not able to apply the url category. But this does not mean that these connections were successfullly established (also because of the app incomplete - I assume the bytes (received/sent) are only a few, not much more that a tcp handshake and a tls handshake).&lt;/P&gt;&lt;P&gt;The firewall has to allow some packets in order to get to the packet where it could allow/deny the traffic based on the actual url.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 21:30:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/202899#M59843</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-28T21:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL matching on wrong URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/203022#M59860</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;Thanks, that makes sense. &amp;nbsp;I didn't realize the handshake is considered a different session than the data that follows it. &amp;nbsp;I also moved the rule down in the list (as it's not as frequently used as others) so other rules are hit first.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 13:59:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-matching-on-wrong-urls/m-p/203022#M59860</guid>
      <dc:creator>mprintz</dc:creator>
      <dc:date>2018-03-01T13:59:49Z</dc:date>
    </item>
  </channel>
</rss>

