<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN based PBF in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-based-pbf/m-p/278769#M75675</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;The customer currently has two internet links, one is for G Suite and the other is for the rest. And a proxy server sits on the latter link. So their&amp;nbsp;PAC file has statement kind of like "direct connect for G Suite URLs and via proxy for the rest".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I want the customer do is to ditch the proxy server for maximum budget allocation to us.&lt;/P&gt;&lt;P&gt;To accomplish this, two internet links are connected to our NGFW and select link based on destination URL which is eventually IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We only can use FQDN object for that purpose but FQDN object doesn't support wildcard FQDN as well as FQDN includes an arbitrary number.&lt;/P&gt;&lt;P&gt;This is why I'm looking for a way to accomplish this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Takahiro&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jul 2019 20:08:57 GMT</pubDate>
    <dc:creator>tmyzw</dc:creator>
    <dc:date>2019-07-24T20:08:57Z</dc:date>
    <item>
      <title>FQDN based PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-based-pbf/m-p/277969#M75534</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a customer who wants to replace proxy servers to NGFW.&lt;/P&gt;&lt;P&gt;The proxy server is used for website filtering as well as URL based routing especially for G Suite.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, PBF policy rule doesn't have URL as match criteria and only FQDN object can be used for that purpose.&lt;/P&gt;&lt;P&gt;But google publishes some wildcard or single digit number URLs as URL list used by G Suite(and Goodle Drive).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ex.&lt;/P&gt;&lt;P&gt;*.drive.google.com&lt;/P&gt;&lt;P&gt;*.clients[N].google.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I want to do is to accomplish URL based (or similar) PBF without proxy server including above URLs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.google.com/a/answer/2589954" target="_blank"&gt;https://support.google.com/a/answer/2589954&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Takahiro&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 04:59:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-based-pbf/m-p/277969#M75534</guid>
      <dc:creator>tmyzw</dc:creator>
      <dc:date>2019-07-22T04:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN based PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-based-pbf/m-p/278381#M75598</link>
      <description>A firewall is not a proxy server, so functionality is different.

What is the use case for only a handful of URLs to be rerouted? there could be a different solution by applying firewall logic to a network issue (rather than proxy logic)

PBF is tcp/udp oriented routing feature, so it functions best at layer3 and below.</description>
      <pubDate>Tue, 23 Jul 2019 13:53:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-based-pbf/m-p/278381#M75598</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-07-23T13:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN based PBF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-based-pbf/m-p/278769#M75675</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;The customer currently has two internet links, one is for G Suite and the other is for the rest. And a proxy server sits on the latter link. So their&amp;nbsp;PAC file has statement kind of like "direct connect for G Suite URLs and via proxy for the rest".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I want the customer do is to ditch the proxy server for maximum budget allocation to us.&lt;/P&gt;&lt;P&gt;To accomplish this, two internet links are connected to our NGFW and select link based on destination URL which is eventually IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We only can use FQDN object for that purpose but FQDN object doesn't support wildcard FQDN as well as FQDN includes an arbitrary number.&lt;/P&gt;&lt;P&gt;This is why I'm looking for a way to accomplish this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Takahiro&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 20:08:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-based-pbf/m-p/278769#M75675</guid>
      <dc:creator>tmyzw</dc:creator>
      <dc:date>2019-07-24T20:08:57Z</dc:date>
    </item>
  </channel>
</rss>

