<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application Blocked instead of URL Block in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229955#M66111</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Even if you don't configure a deny rule yourself, there is a default rule at the end of the policy which is configured by default and cannot be deleted - you can only overwrite it. This default rule at the end is set to no log by default. Right now I assume the application block page comes from there because the action is set to deny and you don't see it in the logs because of the no-log setting. Change that rule or configure your own clean up rule with action drop at the end of the ruleset and try again.&lt;/P&gt;&lt;P&gt;The connection to &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; probably is identified as google-base so it does not hit your URL filtering rule while the connection to google.com the firewall identifies as ssl/web-browsing so it hits your URL filtering rule so the URL block page is shown.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Sep 2018 11:15:39 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-09-07T11:15:39Z</dc:date>
    <item>
      <title>Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229761#M66060</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have implemented URL Filtering. However for http pages, I see Application Blocked page as agains URL Block page.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone experienced same phenomenon?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;RJ&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 16:18:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229761#M66060</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2018-09-06T16:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229792#M66065</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Do you have a rule above the URL filtering rule that blocks specific apps?&lt;/P&gt;&lt;P&gt;Or do you specify apps (web-browsing, ssl, ...) in your URL filtering rule?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 19:17:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229792#M66065</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-06T19:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229817#M66075</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's likely not a 'phenomenon' as you called it (love that word by the way). You likely are running into a proper application block for some reason, whether it's because an application deny policy already exists, or as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;already mentioned you added the application into the URL Filtering deny policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 20:15:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229817#M66075</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-06T20:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229934#M66105</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Security Policy I use applications ssl and web-browsing and Ports tcp/80 and tcp/443.&lt;/P&gt;&lt;P&gt;The Security Policy action is Allow.&lt;/P&gt;&lt;P&gt;Then there is a URL Filtering Profile attached to the security rule, with some URLs allowed and the rest all categories blocked.&lt;/P&gt;&lt;P&gt;The allowed URLs work.&lt;/P&gt;&lt;P&gt;For some of the blocked URLs I see my custom Block Page.&lt;/P&gt;&lt;P&gt;For some of the blocked URLs (predominantly using http) I see the Application Blocked Page instead of my Custom URL Block Page.&lt;/P&gt;&lt;P&gt;I cant pinpoint the problem &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 08:59:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229934#M66105</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2018-09-07T08:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229935#M66106</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No there is no Deny Policy at all. I am implementing the blocking based on URL Filtering Profile. Please read my above post (reply to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;RJ&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 09:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229935#M66106</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2018-09-07T09:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229937#M66107</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;&lt;/P&gt;&lt;P&gt;In your traffic logs: which rule gets hit with these sessions that show the application block page? Is it the interzone-default-deny rule?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 09:29:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229937#M66107</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-07T09:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229953#M66110</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No there is no deny rule. In traffic logs I see the security rule which allows the connection being hit. And nothing in URL filtering logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UPDATE: When I use "www" , I see Application block page and when I access URL without www, then I see my custom URL Block Page.&lt;/P&gt;&lt;P&gt;For example: When I access,&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.google.com" target="_blank"&gt;http://www.google.com&lt;/A&gt; ----&amp;gt;&amp;nbsp;&lt;SPAN&gt;Application Block Page&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://google.com" target="_blank"&gt;http://google.com&lt;/A&gt; ----&amp;gt; Custom URL Block Page&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any Idea why?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 11:01:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229953#M66110</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2018-09-07T11:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229955#M66111</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Even if you don't configure a deny rule yourself, there is a default rule at the end of the policy which is configured by default and cannot be deleted - you can only overwrite it. This default rule at the end is set to no log by default. Right now I assume the application block page comes from there because the action is set to deny and you don't see it in the logs because of the no-log setting. Change that rule or configure your own clean up rule with action drop at the end of the ruleset and try again.&lt;/P&gt;&lt;P&gt;The connection to &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; probably is identified as google-base so it does not hit your URL filtering rule while the connection to google.com the firewall identifies as ssl/web-browsing so it hits your URL filtering rule so the URL block page is shown.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 11:15:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229955#M66111</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-07T11:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229966#M66115</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bingo! Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was exactly the issue:&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I used www, the application that is recognized is different. So as you mentioned in case of &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;, it is google-base and so it hits the default deny rule and so I see application block page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 12:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229966#M66115</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2018-09-07T12:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocked instead of URL Block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229967#M66116</link>
      <description>&lt;P&gt;There are many websites that are defined as applications, so allowing just web browsing and ssl will still block these applications. You have to add them as allowed applications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everytime new content updates come out I always pay close attention to these. We get a lot of "I can't get to this website anymore" tickets, so we try to be proactive in allowing the new definitions.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 12:32:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocked-instead-of-url-block/m-p/229967#M66116</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2018-09-07T12:32:29Z</dc:date>
    </item>
  </channel>
</rss>

