<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering - How does it work exactly with Service interaction in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256032#M72627</link>
    <description>&lt;P&gt;Will test it out tomorrow and cool as a practical matter but any ideas or can point a doc that explains the interaction and OOP between services and url filtering or hell how URL filtering even works in details .. would help with other issues down the road I think.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2019 03:54:27 GMT</pubDate>
    <dc:creator>PeterT</dc:creator>
    <dc:date>2019-04-04T03:54:27Z</dc:date>
    <item>
      <title>URL Filtering - How does it work exactly with Service interaction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256011#M72622</link>
      <description>&lt;P&gt;So let me start here fundementally all I'm trying to do is something like "Computer Y can access MS updates and nothing else" and my three pointers were:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Security-Policy-with-Service-URL-category-configuration/m-p/233176#M66885" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Security-Policy-with-Service-URL-category-configuration/m-p/233176#M66885&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbvCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbvCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHXCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHXCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also as an asside let me say 1) i really hate how often PA KB's conflict each other or do things differently, i.e. is it really that hard to deconflict (i.e. check the URI's listed; yes I understand somebody just went * for one of them) and 2) Why people never do anything in Panorama as it makes following examples / screenshots a PITA; like simpy show/list both ways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyways generally speaking what I want to know, and a search didn't really say anything, is exactly when does URL filtering kick in.&amp;nbsp; Does it kick in after a Service="ssl" or Service="web-browsing" match?&amp;nbsp; Does it kick in regadless of service context the first time it thinks it sees HTTP (or HTTPS)?&amp;nbsp; Basically what is the interaction between "service" and "URL categories".&amp;nbsp; For example if I say "service=web-browing deny; URL Catgory=allow list google.com" does it still let me to google? If say "service=webex allow; URL Category=webex_category deny" does it allow webex.com or not?&amp;nbsp; The specific interaction between those two times when licensed for both is pretty unclear to include OOP.&amp;nbsp; What if I HTTP to a non-standard port, does URL filtering still kick in if it sees HTTP on port 48123? etc.&amp;nbsp; Like I get the context of URL filtering IF service=web-browing (or service=ssl) when they are complimentary but not when it's they are dependency services or the OOP interactions when they conflict.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fundementally in Panorama (to the point) I assume I'm just making a rule that says "allow service=web-browsing/ssl; block-categories all (67) allow list *.microsoft.com" which should work as long service doens't override it.&amp;nbsp; Either way documentation on this could be clearer.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Lastly (since I'm here) do you EVER have to update the PAN-DB URL FIltering database (Device-&amp;gt;licenses) or is this just a one time thing when you first activate your license never to have to do it again until it expires or you wipe the box?&amp;nbsp; It's the only license with an active/download status field hence I've always wondered on that given I can always 'download now' which I find odd as it suggetts it's something you may need to occasionally do but at the same time, it's not a dynamic update. I assume it just autoupdates somehow or it queries real time? LIke I've never understood on teh URL filtering side how those updates are handled.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 00:08:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256011#M72622</guid>
      <dc:creator>PeterT</dc:creator>
      <dc:date>2019-04-04T00:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering - How does it work exactly with Service interaction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256029#M72625</link>
      <description>&lt;P&gt;Here you go.&lt;/P&gt;&lt;P&gt;Ruleset that permits Windows Updates.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rules.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19396i6911D1AB681719E8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rules.PNG" alt="rules.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="object.PNG" style="width: 561px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19397iF5AD27854288A7FB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="object.PNG" alt="object.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PANDB download now button will download seed file.&lt;/P&gt;&lt;P&gt;All other updates are dynamic. You do it only once.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 02:05:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256029#M72625</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-04T02:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering - How does it work exactly with Service interaction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256032#M72627</link>
      <description>&lt;P&gt;Will test it out tomorrow and cool as a practical matter but any ideas or can point a doc that explains the interaction and OOP between services and url filtering or hell how URL filtering even works in details .. would help with other issues down the road I think.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 03:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256032#M72627</guid>
      <dc:creator>PeterT</dc:creator>
      <dc:date>2019-04-04T03:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering - How does it work exactly with Service interaction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256085#M72637</link>
      <description>&lt;P&gt;You mention service many times and then refer to web-browsing or ssl.&lt;/P&gt;&lt;P&gt;I think you mix up with application.&lt;/P&gt;&lt;P&gt;Because service column specifies regular tcp or udp port. Regular Layer 4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my example top rule permits traffic if application is identified as ms-update.&lt;/P&gt;&lt;P&gt;Palo always tries to identify application based on signature or heuristics.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If application signature does not identify this traffic as ms-update then second rule will permit web-browsing or ssl on their regular port (application-default) if it is going to URLs that are specified in custom url category called windows-updates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Simple packet flow in Palo&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Palo packet flow.jpg" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19411iBE802E45B48787B5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Palo packet flow.jpg" alt="Palo packet flow.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And detailed packet flow&lt;/P&gt;&lt;P&gt;&lt;A title="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 14:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256085#M72637</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-04T14:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering - How does it work exactly with Service interaction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256086#M72638</link>
      <description>&lt;P&gt;web-browsing traffic:&lt;/P&gt;&lt;P&gt;SYN&lt;/P&gt;&lt;P&gt;SYN-ACK&lt;/P&gt;&lt;P&gt;ACK&lt;/P&gt;&lt;P&gt;HTTP GET - Palo get's URL and checks the category.&lt;/P&gt;&lt;P&gt;Server sends back website - Palo shifts application from insufficient-data to web-browsing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case of SSL URL is received from data on certificate. So if cert says *.google.com Palo can't identify if user went to mail.google.com or maps.google.com&lt;/P&gt;&lt;P&gt;To get detailed URL categorization you need to decrypt SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://urlfiltering.paloaltonetworks.com/query/" href="https://urlfiltering.paloaltonetworks.com/query/" target="_blank" rel="noopener"&gt;https://urlfiltering.paloaltonetworks.com/query/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 14:28:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256086#M72638</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-04T14:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering - How does it work exactly with Service interaction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256240#M72693</link>
      <description>&lt;P&gt;Thanks for great explanation!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 03:51:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/256240#M72693</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-04-05T03:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering - How does it work exactly with Service interaction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/257354#M73009</link>
      <description>&lt;P&gt;So I'm reading that but not groking the flow exactly even the detailed one.&amp;nbsp; Let me walk you through&amp;nbsp; where my brain is going and ask you clarify:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your first rule it would seem to me that it would allow the source to access the entire web as well including non-MS updates since "web-browsing" is an implicit dependencie of ms-updates (show predefined application ms-update) though I'm not going to lie, my brain has had a hard time groking implicity-use and use applications when it comes to rule evaluation.&amp;nbsp; So my source going to playboy.com would be allowed I assume because of the URL filter "any" coupled with the implicit-use web-browsing for the ms-update application-id, i.e. I feel you still need the the URL filter rule even w/ application=ms-update because of that.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Lets take that a step farther, lets say rule1 = "deny application=ms-update url=windows-update" and rule2 = "allow application=ms-update url=any", in that scenario which rule triggers if I send ms-update to "ninja.com"? Does rule1 trigger because ms-update ignores URL categories regardless of implicit-use so denies it simply based applicatoin-id or does rule2 trigger because implicit-use will get it past rule1?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm trying to figure out (and I can't tell even from the detailed) is the interaction between URL category and application, i.e. are they treated independent of each other (i.e. can I use a URL category w/ app-id SSH for example to block a FQDN) or is URL category a subdependency ONLY of the single application web-browsing and use with any other application (even implicity-use) ignores it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 00:26:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-how-does-it-work-exactly-with-service-interaction/m-p/257354#M73009</guid>
      <dc:creator>PeterT</dc:creator>
      <dc:date>2019-04-12T00:26:14Z</dc:date>
    </item>
  </channel>
</rss>

