<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Object FQDN settings in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226243#M65135</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43193"&gt;@clonesheep&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FQDN objects for services from Google could be problematic anyway as the IP behind the FQDN could change fast and then the firewall does not allow the traffic until the FQDN object os refreshed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case you could use a custom URL category to allow exactly this URL (this requires TLS decryption to work as the firewall only sees &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; without decrypting the traffic)&lt;/P&gt;</description>
    <pubDate>Tue, 07 Aug 2018 09:28:56 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-08-07T09:28:56Z</dc:date>
    <item>
      <title>URL Object FQDN settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226234#M65134</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i must set the firewall to connect to this webpage &lt;A href="http://www.google.com/recaptcha/api/siteverify" target="_blank"&gt;www.google.com/recaptcha/api/siteverify&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have a object -&amp;gt; adress groups -&amp;gt; own address group for some other adresses (like itunes.apple.com and so on. There I musst now inser this domain&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://www.google.com/recaptcha/api/siteverify" target="_blank"&gt;www.google.com/recaptcha/api/siteverify&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;But i Can set this as a FQDN like the others because "The value in this field is invalid."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So anyone an idea how to let the server connect to this domain?&lt;/P&gt;&lt;P&gt;Its for the Sophos Mobile Control service. &lt;A href="https://community.sophos.com/kb/en-us/113217" target="_blank"&gt;https://community.sophos.com/kb/en-us/113217&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 09:22:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226234#M65134</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2018-08-07T09:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: URL Object FQDN settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226243#M65135</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43193"&gt;@clonesheep&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FQDN objects for services from Google could be problematic anyway as the IP behind the FQDN could change fast and then the firewall does not allow the traffic until the FQDN object os refreshed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case you could use a custom URL category to allow exactly this URL (this requires TLS decryption to work as the firewall only sees &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; without decrypting the traffic)&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 09:28:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226243#M65135</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-07T09:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: URL Object FQDN settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226256#M65141</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sounds good.Thanks.&lt;/P&gt;&lt;P&gt;But don`t understand what you mean with TLS decryption?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 09:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226256#M65141</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2018-08-07T09:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: URL Object FQDN settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226257#M65142</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43193"&gt;@clonesheep&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Does the term "SSL decryption" mean more to you? (I try to avoid using the word SSL as this is TLS in the current versions)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I meant you need the firewall to decrypt this HTTPS traffic (--&amp;gt;decryption policiy), because as I wrote the firewall does not see the actual http-get request without decryption.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 09:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226257#M65142</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-07T09:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: URL Object FQDN settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226258#M65143</link>
      <description>&lt;P&gt;ah decryption was no topic until today because we have a ssl proxy.&lt;/P&gt;&lt;P&gt;so is must configure a policies -&amp;gt; decryption -&amp;gt; decryption policy rule ..and what kind of options? SSL Forward Proxy?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 10:15:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226258#M65143</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2018-08-07T10:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: URL Object FQDN settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226260#M65144</link>
      <description>&lt;P&gt;Yes exactly. Because you already use another device for this already you want to make sure that really only this traffic here will be decrypted (server as source and maybe a second custom url category that contains "&lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;")&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 10:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-object-fqdn-settings/m-p/226260#M65144</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-07T10:29:01Z</dc:date>
    </item>
  </channel>
</rss>

