<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: url filtering with Alert category in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314757#M81157</link>
    <description>&lt;P&gt;Well, it could be blocked of you're blocking the High Risk URL category.&amp;nbsp; However, the point I was trying to make is that if Palo has classified that site as High Risk, it's possible someone else has also classified it as a risky site.&amp;nbsp; I'm not sure whether Firefox checks any kind of list for site reputations or anything like that (I haven't used Firefox regularly in over a decade), but if it does, it could be deciding to warn you for that reason.&amp;nbsp; The warning doesn't look like a standard Palo Alto block, but rather a block in Firefox.&amp;nbsp; You really should look at your firewall logs to confirm whether that site is being blocked or allowed.&amp;nbsp; Have you checked there for a log entry?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be a certificate issue, as one of the other comments suggested.&amp;nbsp; If you're doing SSL decryption, I don't think Firefox honors the Windows trusted CA store.&amp;nbsp; I think you have to import the cert directly into Firefox itself.&amp;nbsp; Do you experience the same problem with other browsers?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2020 18:20:13 GMT</pubDate>
    <dc:creator>OwenFuller</dc:creator>
    <dc:date>2020-03-05T18:20:13Z</dc:date>
    <item>
      <title>url filtering with Alert category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314592#M81136</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured the URLs to allow through the firewall with an alert category.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The firewall is allowing the URL but user get the "warning: Potential Security Risk Ahead" page with Go Back (recommended) and Advanced option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any technique to allow user directly go onto the URL page instead go to advanced and continue to the website?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also sent a reclassification request to Palo Alto. It takes 48 hours based on the Palo documentation. I think this is not an issue here. Might be user need to change settings on to their web browser!!&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image006.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24241iB37B1C9BD3514E8C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image006.jpg" alt="image006.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your support.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;CP&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 04:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314592#M81136</guid>
      <dc:creator>ChiragP</dc:creator>
      <dc:date>2020-03-05T04:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering with Alert category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314614#M81138</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104473"&gt;@ChiragP&lt;/a&gt;&amp;nbsp; Check if website have valid certificate. Mostly such errors are due to expired or invalid certificate on websites. Also you can try by adding website in trusted sites to avoid such errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 06:27:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314614#M81138</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-03-05T06:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering with Alert category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314730#M81147</link>
      <description>&lt;P&gt;Palo Alto classifies this URL as High Risk.&amp;nbsp; It could be that Firefox also does some checking of a list of its own, and has determined that it could be an unsafe site.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://urlfiltering.paloaltonetworks.com/query/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/query/&lt;/A&gt;&lt;/P&gt;&lt;UL class="list-unstyled query-result-ul"&gt;&lt;LI&gt;&lt;STRONG&gt;Category&lt;/STRONG&gt;: High Risk&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Description&lt;/STRONG&gt;: Sites that were previously confirmed to be malicious but have displayed benign activity for at least 30 days. Bulletproof ISP-hosted sites and sites with an IP address from an ASN that is known to allow malicious content. Sites that are associated with confirmed malicious activity (for example, they share the same domain). Unknown sites are considered high risk until PAN-DB completes a site analysis and categorization of the site.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 05 Mar 2020 16:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314730#M81147</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-05T16:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering with Alert category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314737#M81149</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are you performing SSL decryption? If yes it could be that the client does not trust the certificate that the PAN is using for the decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The alert selection means that the PAN will log the traffic. That is the only difference between Allow and Alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 17:37:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314737#M81149</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-03-05T17:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering with Alert category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314750#M81154</link>
      <description>&lt;P&gt;Hi OwenFuller,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if Palo classifies the URL as HIgh Risk that could be also blocked, is that right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this could be a browser own check as Mayuer said, however, I would like to know what happens&amp;nbsp;&lt;SPAN&gt;until PAN-DB completes a site analysis and categorization of the site. Is this blocking even though we put the URL under the alert category?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will check today the browser setting and allow URL as trust.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 18:08:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314750#M81154</guid>
      <dc:creator>ChiragP</dc:creator>
      <dc:date>2020-03-05T18:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering with Alert category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314757#M81157</link>
      <description>&lt;P&gt;Well, it could be blocked of you're blocking the High Risk URL category.&amp;nbsp; However, the point I was trying to make is that if Palo has classified that site as High Risk, it's possible someone else has also classified it as a risky site.&amp;nbsp; I'm not sure whether Firefox checks any kind of list for site reputations or anything like that (I haven't used Firefox regularly in over a decade), but if it does, it could be deciding to warn you for that reason.&amp;nbsp; The warning doesn't look like a standard Palo Alto block, but rather a block in Firefox.&amp;nbsp; You really should look at your firewall logs to confirm whether that site is being blocked or allowed.&amp;nbsp; Have you checked there for a log entry?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be a certificate issue, as one of the other comments suggested.&amp;nbsp; If you're doing SSL decryption, I don't think Firefox honors the Windows trusted CA store.&amp;nbsp; I think you have to import the cert directly into Firefox itself.&amp;nbsp; Do you experience the same problem with other browsers?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 18:20:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314757#M81157</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-05T18:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering with Alert category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314760#M81159</link>
      <description>&lt;P&gt;Also, check the URL filtering policy that is attached to your security policy.&amp;nbsp; What are the actions for the financial-services and high-risk categories?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 18:42:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314760#M81159</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-05T18:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: url filtering with Alert category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314842#M81174</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There was a problem with certificate. They have not changed the certificate when moving the site from staging environment to production.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The action for financial services is allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I can say that even if the Palo classifies the URL as a high risk but allow explicitly it works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your time.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 04:09:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-with-alert-category/m-p/314842#M81174</guid>
      <dc:creator>ChiragP</dc:creator>
      <dc:date>2020-03-06T04:09:55Z</dc:date>
    </item>
  </channel>
</rss>

