<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block Dynamic Domain from Security Rulebase in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/334737#M84416</link>
    <description>&lt;P&gt;Already the specified Malicious URL getting a block from URL Filtering and detected in Threat Prevention with action.&lt;/P&gt;&lt;P&gt;it’s a dynamic FQDN/IP that has to block from the security rule base too, but the does not want to add each IP to block as he received every time.&lt;/P&gt;&lt;P&gt;looking for a solution where the dynamic IP can be blocked from the firewall itself so that adding the dynamic IPs or FQDN can be avoided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;apart from EDL there any other option to block the dynamic IP and URL can be block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the URL receives example..&amp;nbsp; &lt;A href="http://www.abc.com" target="_blank"&gt;www.abc.com&lt;/A&gt; / &lt;A href="http://www.abc.2.com" target="_blank"&gt;www.abc.2.com&lt;/A&gt; / &lt;A href="http://www.2.abc.com" target="_blank"&gt;www.2.abc.com&lt;/A&gt; / &lt;A href="http://www.jhs.abc.com" target="_blank"&gt;www.jhs.abc.com&lt;/A&gt; / &lt;A href="http://www.mem1.abc.com" target="_blank"&gt;www.mem1.abc.com&lt;/A&gt; with&lt;/P&gt;&lt;P&gt;dynamic IPs, only common is abc.com rest of are keep on change.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2020 08:33:58 GMT</pubDate>
    <dc:creator>Mohammed_Yasin</dc:creator>
    <dc:date>2020-06-23T08:33:58Z</dc:date>
    <item>
      <title>Block Dynamic Domain from Security Rulebase</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/334737#M84416</link>
      <description>&lt;P&gt;Already the specified Malicious URL getting a block from URL Filtering and detected in Threat Prevention with action.&lt;/P&gt;&lt;P&gt;it’s a dynamic FQDN/IP that has to block from the security rule base too, but the does not want to add each IP to block as he received every time.&lt;/P&gt;&lt;P&gt;looking for a solution where the dynamic IP can be blocked from the firewall itself so that adding the dynamic IPs or FQDN can be avoided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;apart from EDL there any other option to block the dynamic IP and URL can be block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the URL receives example..&amp;nbsp; &lt;A href="http://www.abc.com" target="_blank"&gt;www.abc.com&lt;/A&gt; / &lt;A href="http://www.abc.2.com" target="_blank"&gt;www.abc.2.com&lt;/A&gt; / &lt;A href="http://www.2.abc.com" target="_blank"&gt;www.2.abc.com&lt;/A&gt; / &lt;A href="http://www.jhs.abc.com" target="_blank"&gt;www.jhs.abc.com&lt;/A&gt; / &lt;A href="http://www.mem1.abc.com" target="_blank"&gt;www.mem1.abc.com&lt;/A&gt; with&lt;/P&gt;&lt;P&gt;dynamic IPs, only common is abc.com rest of are keep on change.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 08:33:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/334737#M84416</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-23T08:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Block Dynamic Domain from Security Rulebase</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/334937#M84451</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Depending on what the domain is, a custom vulnerability signature could work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 04:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/334937#M84451</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-24T04:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Block Dynamic Domain from Security Rulebase</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/334973#M84460</link>
      <description>&lt;P&gt;Thanks for the update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a public domain website. and already firewall see has a vulnerability for this site.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 07:55:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/334973#M84460</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-24T07:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Block Dynamic Domain from Security Rulebase</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/335117#M84480</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If the URL filter is flagging it and blocking it, why would you want to block the IP as well? Most sites are hosted by a provider and can we attached to many different sites. Just follow the best practice for URL filtering and DNS sinkhole and let the firewall send telemetry back to PAN so they can update their data bases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 20:47:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/335117#M84480</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-06-24T20:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Block Dynamic Domain from Security Rulebase</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/335265#M84505</link>
      <description>&lt;P&gt;DNS Security feature can detect similar domain&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 11:55:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-dynamic-domain-from-security-rulebase/m-p/335265#M84505</guid>
      <dc:creator>pawelzwierz</dc:creator>
      <dc:date>2020-06-25T11:55:10Z</dc:date>
    </item>
  </channel>
</rss>

