<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom URL Category issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/294287#M77667</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the response. We were able to make it work by changing the Service type to 'any' instead of 'application-default'.&lt;/P&gt;&lt;P&gt;However, this is not good as it allows app-ids to high risk profiles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best practice to structure our rules below?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rules.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21906i75961BC0B0DB6128/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Rules.jpg" alt="Rules.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2019 04:51:56 GMT</pubDate>
    <dc:creator>FarzanaMustafa</dc:creator>
    <dc:date>2019-10-25T04:51:56Z</dc:date>
    <item>
      <title>Custom URL Category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/293131#M77502</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have followed this guide:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail%3Fid%3DkA10g000000ClIPCA0&amp;amp;data=02%7C01%7Csupport-anz%40arrow.com%7C1ef1c9f9ed4b4d5617b508d751f6119c%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C637067989637048680&amp;amp;sdata=WP5C%2BeBfUg2cpZqiZ%2FFMK3okSFu5WWHKyFECbMoG0kU%3D&amp;amp;reserved=0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIPCA0&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Decrypt portion is working well. However we are finding the custom category and its contents although set to block, are not blocking https unless its in the block override.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Example url&amp;nbsp;HTTP results in below block: Correct categorisation block&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Correct.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21810iA32796954C68E7C7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Correct.jpg" alt="Correct.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HTTPS version of the same url (although decrypted) gets blocked by the override block-list from the catchall policy I have in place.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Incorrect.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21811i7F4D9A38C0EE388B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Incorrect.jpg" alt="Incorrect.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 09:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/293131#M77502</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-10-16T09:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/293170#M77512</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Look at your system logs and verify that you are actually hitting the proper security policy where the URL category is applied. If you are not, then please post the entry you are actually trying to map on and the URL that isn't being caught.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 17:55:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/293170#M77512</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-10-16T17:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/294287#M77667</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the response. We were able to make it work by changing the Service type to 'any' instead of 'application-default'.&lt;/P&gt;&lt;P&gt;However, this is not good as it allows app-ids to high risk profiles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best practice to structure our rules below?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rules.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21906i75961BC0B0DB6128/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Rules.jpg" alt="Rules.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 04:51:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/294287#M77667</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-10-25T04:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/294494#M77691</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'd really need to take a look at your application filters and see what applications they are matching to be sure; but when you start decrypting traffic one of the primary issues you'll run across is that web-browsing will map to tcp-443 (due to decryption) and that doesn't work with application-default policies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would try your same policy, but make a subsequent policy that allows web-browsing on service object service-https and see if that doesn't fix the issues that you were running into without the 'any' policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 20:47:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/294494#M77691</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-10-25T20:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Custom URL Category issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/295330#M77817</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Noticing the destination nat port, we modified the security policy to be&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;App-id = web-browsing and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Service = custom service group of port 80 and 443.&amp;nbsp; This appears to have resolve the issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 02:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-issue/m-p/295330#M77817</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-10-31T02:09:45Z</dc:date>
    </item>
  </channel>
</rss>

