<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regular expressions in URL filtering in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9774#M7170</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any chance there will be support for regular expressions in URL block/allow lists and custom URL groups? It is annoying to have to enter both a base domain name and the domain name with "*." to completely allow/deny a domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be much preferred if I could put a single line that covered both "exampledomain.com" and "www.exampledomain.com" and gain the additional ability to do something like allow/deny exampledomain.com/examplepath[0-9]/* should I want to do so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my understanding this isn't currently implemented, but I would love to see it as a feature in the future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Mar 2010 21:03:24 GMT</pubDate>
    <dc:creator>nftechservices</dc:creator>
    <dc:date>2010-03-25T21:03:24Z</dc:date>
    <item>
      <title>Regular expressions in URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9774#M7170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any chance there will be support for regular expressions in URL block/allow lists and custom URL groups? It is annoying to have to enter both a base domain name and the domain name with "*." to completely allow/deny a domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be much preferred if I could put a single line that covered both "exampledomain.com" and "www.exampledomain.com" and gain the additional ability to do something like allow/deny exampledomain.com/examplepath[0-9]/* should I want to do so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my understanding this isn't currently implemented, but I would love to see it as a feature in the future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Mar 2010 21:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9774#M7170</guid>
      <dc:creator>nftechservices</dc:creator>
      <dc:date>2010-03-25T21:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expressions in URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9775#M7171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;currently there is no support for regualar expressions in url filtering.&lt;/P&gt;&lt;P&gt;There is also not a plan to support regular expressions in url filtering as it would be very resource intensive/expensive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Mar 2010 22:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9775#M7171</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-03-25T22:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expressions in URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9776#M7172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about making the PAN to automatically include subdomains when you create the basedomain in the urlfilter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you only have to write:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;youtube.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;instead of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;youtube.com&lt;/P&gt;&lt;P&gt;*.youtube.com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Mar 2010 05:04:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9776#M7172</guid>
      <dc:creator>rps</dc:creator>
      <dc:date>2010-03-26T05:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expressions in URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9777#M7173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with rps... We have a huge list of custom URL's that we want to block and it would make it twice as huge to have to write both the domain name and the wildcard for the subdomains.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Oct 2010 19:15:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9777#M7173</guid>
      <dc:creator>kbernard</dc:creator>
      <dc:date>2010-10-12T19:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expressions in URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9778#M7174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;I'm resurrecting this post as this is something that has always bothered me about PAN OS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;@kbernard Sometimes it doesn't only double.&amp;nbsp; As an example, I've seen content delivery networks and many popular social networking sites that have a ridiculous amount of nested sub domains.&amp;nbsp; In these cases you will find yourself creating multiple "per period delimited wildcard" entries for every child of a zone.&amp;nbsp; As an example consider the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;pdf.downloads.cd.foo.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;To ensure you allow each sub domain that could potentially exist as a descendant of foo.com you would need the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;foo.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;*.foo.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;*.*.foo.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;*.*.*.foo.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;As a suggestion to Palo Alto Networks, Why not follow the RFCs that govern DNS, they certainly seem applicable in this situation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;When dealing with wildcard resource records, the "*" label will match any descendant of &amp;lt;anydomain&amp;gt; while not affecting &amp;lt;anydomain&amp;gt; itself.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;@swhyte The "limited wildcard" delimited by a period label "." seems unnecessary and TBH more resource intensive/expensive than the alternative.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Mar 2011 22:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9778#M7174</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2011-03-30T22:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expressions in URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9779#M7175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@rroberts - I agree about moving to the RFC standard. When we used Websense we just entered the root domain and the product took care of the primary domain and all subdomains automatically. I know this could be potentially problematic if you wanted to block the main domain only, or some combination of it and some of the subdomains, but this can easily be worked around with exceptions/whitelisting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Mar 2011 22:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9779#M7175</guid>
      <dc:creator>kbernard</dc:creator>
      <dc:date>2011-03-30T22:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expressions in URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9780#M7176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way around this?&lt;/P&gt;&lt;P&gt;what we see is that when we block *.*.foo.com - All surfing over the internet is being blocked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 15:18:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9780#M7176</guid>
      <dc:creator>support6</dc:creator>
      <dc:date>2011-07-27T15:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expressions in URL filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9781#M7177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The multi wildcard in a *.* format is unsupported and it would block all raffic if added to a block list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The example you gave shold be *.foo.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 20:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regular-expressions-in-url-filtering/m-p/9781#M7177</guid>
      <dc:creator>pkruse</dc:creator>
      <dc:date>2011-08-08T20:43:39Z</dc:date>
    </item>
  </channel>
</rss>

