<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding ?v=panosurl to MineMeld EDL brought down our entire network in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/244599#M69787</link>
    <description>&lt;P&gt;One of customer seemed having same issue. what is the solution for this ? PAN-OS in 8.1.4 release.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Dec 2018 23:14:06 GMT</pubDate>
    <dc:creator>dannadurai</dc:creator>
    <dc:date>2018-12-28T23:14:06Z</dc:date>
    <item>
      <title>Adding ?v=panosurl to MineMeld EDL brought down our entire network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/220352#M63569</link>
      <description>&lt;P&gt;Just wanted to share this with the community in hopes that it may prevent one from experiencing the hardship that we did. We use MineMeld with our URL filtering rules. We appended "&lt;SPAN&gt;?v=panosurl" to the end of the&amp;nbsp; end of the URL for our General_Block_List with the assumption that&amp;nbsp; it would just reformat the output essentially removing the "http://" from the URLs in the list.&amp;nbsp; Unfortunately adding&amp;nbsp;?v=panosurl to the end of the URL caused the list to add three entries for *.com and one for *.it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Since this EDL was a block list it essentially began blocking everything to those TLDs. This brought the entire network to it's knees and we couldn't get into our Panorama server to revert the change. We were eventually able to access the Panorama server via the CLI and revert the changes.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Just beware and do your due diligence&amp;nbsp;when implementing this on your EDLs.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 13:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/220352#M63569</guid>
      <dc:creator>Mike.ship</dc:creator>
      <dc:date>2018-07-03T13:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ?v=panosurl to MineMeld EDL brought down our entire network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/244599#M69787</link>
      <description>&lt;P&gt;One of customer seemed having same issue. what is the solution for this ? PAN-OS in 8.1.4 release.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Dec 2018 23:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/244599#M69787</guid>
      <dc:creator>dannadurai</dc:creator>
      <dc:date>2018-12-28T23:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ?v=panosurl to MineMeld EDL brought down our entire network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/244733#M69814</link>
      <description>&lt;P&gt;Thanks for the post; although I found it after I had experienced the same thing; however, my list did not include a *.com or *.it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;name@fw(active)&amp;gt;&amp;nbsp; request system external-list show type ip name edl-phishing-sites&amp;nbsp;&lt;BR /&gt;vsys1/edl-phishing-sites:&lt;BR /&gt;Next update at : Thu Dec 27 16:00:02 2018&lt;BR /&gt;Source : &lt;A href="https://10.x.x.x/feeds/phishing-url?v=panosurl" target="_blank"&gt;https://10.x.x.x/feeds/phishing-url?v=panosurl&lt;/A&gt;&lt;BR /&gt;Referenced : Yes&lt;BR /&gt;Valid : Yes&lt;BR /&gt;Auth-Valid : Yes&lt;/P&gt;&lt;P&gt;Total valid entries : 2013&lt;BR /&gt;Total invalid entries : 59&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Went through the entire text and did not find a string or consecutive wildcards together. Can't figure out why this would have recategorized pretty much every common domain as edl-phishing-sites. Thankfully I deny all traffic to those sites with my policy. We had a connectivity issue for about 5 minutes until I could back everything out. What a pita.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2019 22:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/244733#M69814</guid>
      <dc:creator>craigomatic</dc:creator>
      <dc:date>2019-01-02T22:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ?v=panosurl to MineMeld EDL brought down our entire network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/260646#M73886</link>
      <description>&lt;P&gt;Today I had the same issue and I think I found the reason. I have compared the lists with and without ?v=panosurl and I found some problems with different enties. Entries in minemeld like *domain.tld will be changed to *.tld after adding the parameter to the url. I also found a typo in a manually entered indicator. This one was *:acbay.com and was also changed to *.com after adding panosurl to the url ...&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 23:14:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/260646#M73886</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-12T23:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ?v=panosurl to MineMeld EDL brought down our entire network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/260778#M73924</link>
      <description>&lt;P&gt;So do you think there is an issue with the parser? What PANOS version are you running? I still have not moved forward in implementing due to the high risk/low payoff and there seems to be a question whether this is really happening. Sorry it happened to you but I'm also glad I'm not crazy.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 16:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/260778#M73924</guid>
      <dc:creator>craigomatic</dc:creator>
      <dc:date>2019-05-13T16:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ?v=panosurl to MineMeld EDL brought down our entire network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/260800#M73927</link>
      <description>&lt;P&gt;To me this definately is an issue in the parser. Even if "*abc.com" isn't a valid entry on a paloalto firewall, changing this to "*.com" cannot be right. In my opinion the best would be if ?v=panosurl does the same as a paloalto firewall does (in addition to removing http:// and https://), such entries should simply be ignored.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 18:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/260800#M73927</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-13T18:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ?v=panosurl to MineMeld EDL brought down our entire network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/383301#M89943</link>
      <description>&lt;P&gt;I had a similar experience where implementing the ?v=panosurl caused a huge spike in CPU on our PA5220s we couldn't commit configuration changes.&amp;nbsp; &amp;nbsp;I was kind of shocked that making what was recommended as a change would have such dire effects on our envorironment.&amp;nbsp; Has anyone used it successfully?&amp;nbsp; If not,&amp;nbsp; do you have a work around to make edl ses feeds from minemeld usable for URL filetering?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 19:38:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-v-panosurl-to-minemeld-edl-brought-down-our-entire/m-p/383301#M89943</guid>
      <dc:creator>datuttle</dc:creator>
      <dc:date>2021-02-01T19:38:04Z</dc:date>
    </item>
  </channel>
</rss>

