<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HELP: How to block access to any site except those on a whitelist... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214907#M62412</link>
    <description>&lt;OL&gt;&lt;LI&gt;Configure and enable TLS decryption*:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/configure-ssl-forward-proxy" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/configure-ssl-forward-proxy&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Create a custom URL category with your entries&lt;/LI&gt;&lt;LI&gt;Create a security policy where you add your custom URL category directly into your rule (in the service tab)&lt;/LI&gt;&lt;LI&gt;Do not create any other rule except a deny-all rule for that zone&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;*without TLS decryption you'll be only able to filter for the domainname but not&amp;nbsp;&lt;SPAN&gt;edition.cnn.com&lt;STRONG&gt;/health&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 21 May 2018 20:04:56 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-05-21T20:04:56Z</dc:date>
    <item>
      <title>HELP: How to block access to any site except those on a whitelist...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214897#M62411</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a certain Zone I need to &lt;STRONG&gt;block access to anything else but these URLs&lt;/STRONG&gt; on a whitelist like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;edition.cnn.com/health&lt;BR /&gt;edition.cnn.com/travel&lt;BR /&gt;money.cnn.com/technology/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I do that most elegantly (I have a VM-100 with latest PanOS)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for a quick reply on this, I have tried with URL filtering but to no avail...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tor&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 19:43:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214897#M62411</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2018-05-21T19:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: HELP: How to block access to any site except those on a whitelist...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214907#M62412</link>
      <description>&lt;OL&gt;&lt;LI&gt;Configure and enable TLS decryption*:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/configure-ssl-forward-proxy" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/configure-ssl-forward-proxy&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Create a custom URL category with your entries&lt;/LI&gt;&lt;LI&gt;Create a security policy where you add your custom URL category directly into your rule (in the service tab)&lt;/LI&gt;&lt;LI&gt;Do not create any other rule except a deny-all rule for that zone&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;*without TLS decryption you'll be only able to filter for the domainname but not&amp;nbsp;&lt;SPAN&gt;edition.cnn.com&lt;STRONG&gt;/health&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 20:04:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214907#M62412</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-21T20:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: HELP: How to block access to any site except those on a whitelist...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214910#M62413</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have actually tried to create a custom URL category as you suggest using create URL Filtering Profile / Override tab and entered the list of 'white' URL's in the left (Allow List) listbox.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secondly I added this profile to the Security policy for the Zone in question.&amp;nbsp; However, despite this, it unfortunately still allows traffic from any URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing..?&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 20:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214910#M62413</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2018-05-21T20:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: HELP: How to block access to any site except those on a whitelist...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214911#M62414</link>
      <description>&lt;P&gt;If you use your method: have you set every URL category to block?&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 20:21:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-how-to-block-access-to-any-site-except-those-on-a-whitelist/m-p/214911#M62414</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-21T20:21:04Z</dc:date>
    </item>
  </channel>
</rss>

