<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring XFF logging without a URL Filtering License in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-xff-logging-without-a-url-filtering-license/m-p/244632#M69795</link>
    <description>&lt;P&gt;To prevent additional information leakage of the IP address, you should enable this option (Device&amp;gt;Setup&amp;gt;Content-ID&amp;gt;X-Forwarder-for Headers):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20181230-215434_Chrome.jpg" style="width: 523px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18129iF77C564C117C9811/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_20181230-215434_Chrome.jpg" alt="Screenshot_20181230-215434_Chrome.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Dec 2018 20:57:41 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-12-30T20:57:41Z</dc:date>
    <item>
      <title>Configuring XFF logging without a URL Filtering License</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-xff-logging-without-a-url-filtering-license/m-p/239987#M68745</link>
      <description>&lt;P&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt; Create a Custom URL Category with * under ‘sites’ (Objects &amp;gt;&amp;gt; Custom Objects &amp;gt;&amp;gt; URL Category &amp;gt;&amp;gt; Add)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 729px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17814i1425ED25A966EB3C/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.88px;"&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt; Create a URL Filtering Profile &amp;amp; set your Custom Category action to “alert” (Objects &amp;gt;&amp;gt; Security Profiles &amp;gt;&amp;gt; URL Filtering &amp;gt;&amp;gt; Add)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 725px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17815iE5F7E6D252A54EA6/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tick the box to log XFF on the ‘URL Filtering Settings’ tab…&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 727px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17816i5BF26B2E83B5B664/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3.&lt;/STRONG&gt; Create a syslog server profile &amp;amp; modify the custom log format settings for URL (Device &amp;gt;&amp;gt; Server Profiles &amp;gt;&amp;gt; Syslog &amp;gt;&amp;gt; Add)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 739px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17817iCF8B1A96FA8A3225/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 735px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17818i2BD2CF790B371CC7/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;IMG class="lia-image-display" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17819iD04D6291913F0A94/image-size/large?v=1.0&amp;amp;px=-1" border="0" width="733" height="511" data-lia-image-count="6" title="6.png" alt="6.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;4.&lt;/STRONG&gt; Create a Log Forwarding Profile &amp;amp; point it at your syslog server (Objects &amp;gt;&amp;gt; Log Forwarding &amp;gt;&amp;gt; Add)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;I class="lia-fa lia-fa-pencil lia-image-edit-icon"&gt;&lt;/I&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 736px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17820iA9924A41FB47D3D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure your Log Type is ‘url’…&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 730px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17821i048BAE2E7CCD0DE5/image-size/large?v=v2&amp;amp;px=999" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;5.&lt;/STRONG&gt; Apply both the URL Filtering &amp;amp; Log Forwarding Profiles to your Security Policy rules (Policies &amp;gt;&amp;gt; Security)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG class="lia-image-display" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17822i99D48CE77DB609B9/image-size/large?v=1.0&amp;amp;px=-1" border="0" width="732" height="485" data-lia-image-count="9" title="9.png" alt="9.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;6.&lt;/STRONG&gt; Commit your configuration, and observe this expected warning message&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.png" style="width: 732px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17822i99D48CE77DB609B9/image-size/large?v=v2&amp;amp;px=999" role="button" title="9.png" alt="9.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;7.&lt;/STRONG&gt; To test, you can use a free extension to Firefox called “Modify Header Value (HTTP Headers) by Milen Monrov. Type ‘about:addons’, click on ‘More’ &amp;amp; scroll down.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;You will have an opportunity to setup a header insertion rule like I have…&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 711px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17829i2C490603E880AC7B/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I scroll to the right, you can see I am inserting a value of 1.1.1.1…&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.png" style="width: 734px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17828i9492453FF58339CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.png" alt="12.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;8.&lt;/STRONG&gt; Pick a cleartext site against which you can validate that the header insertion is working (I use &lt;A href="http://www.xhaus.com/headers" target="_blank"&gt;http://www.xhaus.com/headers&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.png" style="width: 737px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17827i8EEC9D7F8B274247/image-size/large?v=v2&amp;amp;px=999" role="button" title="13.png" alt="13.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;9.&lt;/STRONG&gt; Validate that the log data being sent by the firewall includes your expected values (ultimately this will match the string setting from step #3 above, which in my case is sip=$src,xff=$xff,dip=$dst,url=$misc). &amp;nbsp;you can apply the wireshark display filter 'syslog' to match only what we are after...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="14.png" style="width: 738px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17826i58CD0608D5950693/image-size/large?v=v2&amp;amp;px=999" role="button" title="14.png" alt="14.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; Your browser will likely be sending traffic in the background that does not fire the XFF extension tool (safe browsing, etc.). Do not be alarmed if this type of traffic&amp;nbsp;does not display an XFF value.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 08:59:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-xff-logging-without-a-url-filtering-license/m-p/239987#M68745</guid>
      <dc:creator>BrianTaggart</dc:creator>
      <dc:date>2018-12-06T08:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring XFF logging without a URL Filtering License</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-xff-logging-without-a-url-filtering-license/m-p/242809#M69435</link>
      <description>&lt;P&gt;Great artical! Very useful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One small note - on step 6 I believe you got the wrong screenshot. I guess you wanted to should the warning for the no valid URL filtering during commit?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 07:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-xff-logging-without-a-url-filtering-license/m-p/242809#M69435</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2018-12-11T07:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring XFF logging without a URL Filtering License</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-xff-logging-without-a-url-filtering-license/m-p/244632#M69795</link>
      <description>&lt;P&gt;To prevent additional information leakage of the IP address, you should enable this option (Device&amp;gt;Setup&amp;gt;Content-ID&amp;gt;X-Forwarder-for Headers):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20181230-215434_Chrome.jpg" style="width: 523px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18129iF77C564C117C9811/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_20181230-215434_Chrome.jpg" alt="Screenshot_20181230-215434_Chrome.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Dec 2018 20:57:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-xff-logging-without-a-url-filtering-license/m-p/244632#M69795</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-12-30T20:57:41Z</dc:date>
    </item>
  </channel>
</rss>

