<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTP Header Referrer in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/204165#M60084</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;is it possible to build a security access rule based on http-header referrer field?&lt;/P&gt;&lt;P&gt;Someone have do it?&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 07 Mar 2018 19:33:51 GMT</pubDate>
    <dc:creator>mmcastr</dc:creator>
    <dc:date>2018-03-07T19:33:51Z</dc:date>
    <item>
      <title>HTTP Header Referrer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/204165#M60084</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;is it possible to build a security access rule based on http-header referrer field?&lt;/P&gt;&lt;P&gt;Someone have do it?&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 19:33:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/204165#M60084</guid>
      <dc:creator>mmcastr</dc:creator>
      <dc:date>2018-03-07T19:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Header Referrer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/204216#M60093</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65177"&gt;@mmcastr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Kinda. The only way I can think of to actually acomplish this would be to build a custom application based on HTTP-Headers. If you do a pattern match you shouldn't have an issue pulling the referrer information. Then you can allow/block this application through your security policies.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 22:02:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/204216#M60093</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-07T22:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Header Referrer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/204546#M60156</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;We have a scenario where Internet access is blocked by default for most of users and the access is allowed by a custom URL object that have a list of URL or FQDN.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I found a traffic related to one of the allowed FQDN that uses http referrer but is denied because the FQDN inside the URI is not inside the white list but it has into the http referrer the allowed FQDN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on it I'm trying to allow this traffic based in this http field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't find the http referrer attribute inside the available options to http protocol when I was building the custom app.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As we don't have a testing environment to homologate this custom app I'd like to ask you if I'm in the right way to match this kind of traffic and allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below I put the options I worked to build the custom app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application / Signatures&lt;BR /&gt;&amp;nbsp; Signatures Name: http-scup&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Scope: Transaction&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Operator: Pattern Match&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Context: http-req-params&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Pattern: &lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Qualifier: http-method GET&lt;BR /&gt;&lt;BR /&gt;Thanks for your time.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 13:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/204546#M60156</guid>
      <dc:creator>mmcastr</dc:creator>
      <dc:date>2018-03-09T13:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Header Referrer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/1232576#M124657</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65177"&gt;@mmcastr&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="QcsUad BDJ8fb sMVRZe hCXDsb wneUed"&gt;
&lt;DIV class="usGWQd"&gt;
&lt;DIV class="KkbLmb"&gt;
&lt;DIV class="lRu31" dir="ltr"&gt;I'm in the same situation.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;Did you solve it?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="messageEditor_65301610449b37_0" class="MessageEditor"&gt;&lt;A id="previewButton_65301610449b37_64783" class="lia-link-navigation lia-message-editor-preview-button" href="https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/td-p/204165#" target="_blank"&gt;Preview&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 25 Jun 2025 12:22:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-referrer/m-p/1232576#M124657</guid>
      <dc:creator>SoporteFABA</dc:creator>
      <dc:date>2025-06-25T12:22:16Z</dc:date>
    </item>
  </channel>
</rss>

