<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic URL Category in Security Policy only for http? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253322#M71952</link>
    <description>&lt;P&gt;We unfortunately use a smtp server with fqdn. (cannot use fqdn object for certain reasons)&lt;/P&gt;&lt;P&gt;And we implemented a security policy with the url category in the "Service/URL Category" section of the security policy.&lt;/P&gt;&lt;P&gt;In the security policy, the application allowed is smtp and port allowed is 25.&lt;/P&gt;&lt;P&gt;When we test, the connection does not match this rule at all. We are making sure that indeed the application tirggered is smtp on port 25.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So is URL Category in Security Policy only applied when the application is web-browsing/ssl and port is 80/443 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;RJ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 12:46:23 GMT</pubDate>
    <dc:creator>rjdahav163</dc:creator>
    <dc:date>2019-03-12T12:46:23Z</dc:date>
    <item>
      <title>URL Category in Security Policy only for http?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253322#M71952</link>
      <description>&lt;P&gt;We unfortunately use a smtp server with fqdn. (cannot use fqdn object for certain reasons)&lt;/P&gt;&lt;P&gt;And we implemented a security policy with the url category in the "Service/URL Category" section of the security policy.&lt;/P&gt;&lt;P&gt;In the security policy, the application allowed is smtp and port allowed is 25.&lt;/P&gt;&lt;P&gt;When we test, the connection does not match this rule at all. We are making sure that indeed the application tirggered is smtp on port 25.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So is URL Category in Security Policy only applied when the application is web-browsing/ssl and port is 80/443 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;RJ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:46:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253322#M71952</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2019-03-12T12:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category in Security Policy only for http?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253330#M71953</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any application with a dependency on web-browsing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:15:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253330#M71953</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-03-12T13:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category in Security Policy only for http?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253337#M71955</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply! But then how to solve the issue:&lt;/P&gt;&lt;P&gt;We want to allow smtp on port 25 only as application and destination is a url category, attached in "service/url category" of a security policy. (We are not using fqdn object because the refresh time can be minimum only 10 minutes and the server changes the ip more frequently)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;RJ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253337#M71955</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2019-03-12T13:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category in Security Policy only for http?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253339#M71957</link>
      <description>&lt;P&gt;to answer your first question "&lt;SPAN&gt;So is URL Category in Security Policy only applied when the application is web-browsing/ssl and port is 80/443 ?" i believe the answer is no.&amp;nbsp; the url category can match on any port or application.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as for a possible solution to the problem;&amp;nbsp; have you tried using a seperate security profile with a custom url-filtering profile that allows the category?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253339#M71957</guid>
      <dc:creator>BetterGriffin</dc:creator>
      <dc:date>2019-03-12T14:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category in Security Policy only for http?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253374#M71962</link>
      <description>&lt;P&gt;If you cannot use the fqdn, I would create an address group with all the possible IP's the fqdn resolves to and use that as the destination.&lt;/P&gt;&lt;P&gt;(If it changes so rapidly, I presume it's for load balancing and the number of IP's will be limited...)&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 17:09:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253374#M71962</guid>
      <dc:creator>CHKlomp</dc:creator>
      <dc:date>2019-03-12T17:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: URL Category in Security Policy only for http?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253519#M71975</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any application with a dependency on web-browsing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers !&lt;/P&gt;&lt;P&gt;-Kiwi.&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;May I add that you can use URL categories not only for web-browsing dependent applications. Actually also for almost every TLS encrypted connection like SMTPs. So if your connection is encrypted the solution with an URL category probably works as the firewalls also checks for hostnames in the SNI extension and also the CN of a certificate in a TLS connection.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 22:08:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-category-in-security-policy-only-for-http/m-p/253519#M71975</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-03-12T22:08:27Z</dc:date>
    </item>
  </channel>
</rss>

