<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic custom url category with non http and https port. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350774#M87000</link>
    <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I Have created custom URL category e.g&amp;nbsp; category name (*.xyz.com) Now I want to create inbound rule like below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source zone :- Internet&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination Zone :- LAN&lt;/P&gt;&lt;P&gt;Destination IP :- Any&lt;/P&gt;&lt;P&gt;Port :- 389 , 4172&lt;/P&gt;&lt;P&gt;URL Categary :- 'Custome category'&lt;/P&gt;&lt;P&gt;Security Profile : Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My doubt is will this work on port 389 and 4172 port or this will work only on http and https port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dhananjay Bhakte&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Sep 2020 06:15:36 GMT</pubDate>
    <dc:creator>DhananjayBhakte</dc:creator>
    <dc:date>2020-09-21T06:15:36Z</dc:date>
    <item>
      <title>custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350774#M87000</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I Have created custom URL category e.g&amp;nbsp; category name (*.xyz.com) Now I want to create inbound rule like below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source zone :- Internet&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination Zone :- LAN&lt;/P&gt;&lt;P&gt;Destination IP :- Any&lt;/P&gt;&lt;P&gt;Port :- 389 , 4172&lt;/P&gt;&lt;P&gt;URL Categary :- 'Custome category'&lt;/P&gt;&lt;P&gt;Security Profile : Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My doubt is will this work on port 389 and 4172 port or this will work only on http and https port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dhananjay Bhakte&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 06:15:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350774#M87000</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2020-09-21T06:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350795#M87005</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you please clarify what you are trying to achieve here? The application and the service are independend of each other. You can easily create a rule allowing SSL and Web-Browsing on port 389 and 4172.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 07:58:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350795#M87005</guid>
      <dc:creator>Rene_Boehme</dc:creator>
      <dc:date>2020-09-21T07:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350797#M87007</link>
      <description>&lt;P&gt;HI Rene,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have requirement from customer to open port 389 and 4172 for eg *.xyz domain.&lt;/P&gt;&lt;P&gt;So I created custom category *.xyz.com and have to create rule by calling this category into rule and will allow only 389 and 4172 ports.&lt;/P&gt;&lt;P&gt;As far my understanding url category work only for ssl and web-browsing traffic, so just wanted to know if I keep url category in rule for port port 389 and 4172 will that rule work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dhananjay&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350797#M87007</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2020-09-21T08:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350798#M87008</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ok now I got you. So you are correct URL filtering is working with http/https only. Futhermore it is kind of uncommon to have URL filtering active in inwards direction. So I saw the request for port 389 which is basically LDAP, dont know for 4172. However please make yourself familiar with the conecpt of an "application firewall" - we do not open ports anymore. But in term of customers request you are right, this is not going to work.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:48:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350798#M87008</guid>
      <dc:creator>Rene_Boehme</dc:creator>
      <dc:date>2020-09-21T08:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350817#M87010</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129413"&gt;@DhananjayBhakte&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds like you need FQDN not URL.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use FQDN object as source or destination address in the policy. Firewall will query the DNS server and use this fqdn to resolve it to IP address. The received IP will be cached for configured amount of time (probably 30min was the default, but not sure).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given the port from your description it sound be more reasonable to use FQDN instead of URL filtering.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be more precise URL custom category&amp;nbsp; will work with web-based application. If you think for a bit it is logical - firewall needs to know which part of the traffic is the URL, so it doesn't matter what port you are using&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 10:49:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350817#M87010</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-09-21T10:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350849#M87012</link>
      <description>&lt;P&gt;HI Alexzandar,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic is not URL traffic and its application is not applicable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For known fqdn e.g abc.xyz.com it is possible to write rule however fqdn is not fixed, customer says fqdn will change every time but domain (xyz.com) would be fixed, So my query is Can I allow wildcast *.xyz.com instead of single fqdn in security policy using custom url category for custom ports.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dhananjay Bhakte&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 12:50:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/350849#M87012</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2020-09-21T12:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/352051#M87126</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129413"&gt;@DhananjayBhakte&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;HI &lt;A title="tellthebell" href="https://www.tellthebell.one/" target="_blank" rel="noopener"&gt;tellthebell&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic is not URL traffic and its application is not applicable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For known fqdn e.g abc.xyz.com it is possible to write rule however fqdn is not fixed, customer says fqdn will change every time but domain (xyz.com) would be fixed, So my query is Can I allow wildcast *.xyz.com instead of single fqdn in security policy using custom url category for custom ports.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dhananjay Bhakte&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;You can use FQDN object as source or destination address in the policy. Firewall will query the DNS server and use this fqdn to resolve it to IP address. The received IP will be cached for configured amount of time (probably 30min was the default, but not sure).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given the port from your description it sound be more reasonable to use FQDN instead of URL filtering.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 04:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/352051#M87126</guid>
      <dc:creator>couvertjy</dc:creator>
      <dc:date>2020-09-28T04:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/352982#M87261</link>
      <description>&lt;P&gt;HI Couvertjy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I allow policy as below,&lt;/P&gt;&lt;P&gt;Source Zone :- Internet&lt;/P&gt;&lt;P&gt;Source IP address:-&amp;nbsp; x.x.x.x&lt;/P&gt;&lt;P&gt;Destination Zone :- Lan&lt;/P&gt;&lt;P&gt;Destination IP address:- Any&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Custom URL Categary :- *.xyz.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Port :389 and 8759&lt;/P&gt;&lt;P&gt;Action : Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is working, but my question is still there as *.xyz.com is hosted on internet so how can firewall allowing&amp;nbsp; xyz.com fqdn to access ports on Lan zone through Custom URL category?. So here URL category is acting as source IP . So is it possible that custom url category can act as source or destination IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dhananjay Bhakte&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 13:43:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/352982#M87261</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2020-09-30T13:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/352983#M87262</link>
      <description>&lt;P&gt;let me correct my below comment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source IP also any&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source Zone :- Internet&lt;/P&gt;&lt;P&gt;Source IP address:-&amp;nbsp; any&lt;/P&gt;&lt;P&gt;Destination Zone :- Lan&lt;/P&gt;&lt;P&gt;Destination IP address:- Any&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Custom URL Categary :- *.xyz.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Port :389 and 8759&lt;/P&gt;&lt;P&gt;Action : Allow&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 13:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/352983#M87262</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2020-09-30T13:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/423405#M94158</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to above query, I got new requirement from customer as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source Zone : trust&lt;/P&gt;&lt;P&gt;Source user :- abc&lt;/P&gt;&lt;P&gt;Destination Zone :- Untrust(internet)&lt;/P&gt;&lt;P&gt;Destination :-&amp;nbsp; *.ncra.tifr.res.in&lt;/P&gt;&lt;P&gt;Port : 22&lt;/P&gt;&lt;P&gt;Application: SSH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to achieve above requirement&amp;nbsp; , I have created custom url category as *.ncra.tifr.res.in and created rule as below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy :--&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source Zone : trust&lt;/P&gt;&lt;P&gt;Source user :- abc&lt;/P&gt;&lt;P&gt;Destination Zone :- Untrust(internet)&lt;/P&gt;&lt;P&gt;Destination :-&amp;nbsp; any&lt;/P&gt;&lt;P&gt;Port : 22&lt;/P&gt;&lt;P&gt;url category :- *.&amp;nbsp;ncra.tifr.res.in&lt;/P&gt;&lt;P&gt;Application: SSH&lt;/P&gt;&lt;P&gt;Profile :- None&lt;/P&gt;&lt;P&gt;Action :- Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However it is not working.&lt;/P&gt;&lt;P&gt;Note :- Customer&amp;nbsp; dont have fqdn he provided *.ncra.tifr.res.in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I wanted to know that&amp;nbsp; *.ncra.tifr.res.in custom category not work for application other than web browsing and ssl?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dhananjay&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 13:13:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/423405#M94158</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2021-07-30T13:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/423542#M94183</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129413"&gt;@DhananjayBhakte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Custom URL categories only work for http and TLS traffic - not only for apps web-browsing and ssl as there are quite a few more that are based on http/tls traffic - but at least for ssh you cannot use a custom URL category.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 19:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/423542#M94183</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-30T19:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/423714#M94203</link>
      <description>&lt;P&gt;Thanks Cyber Elite I Got it now......... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 03:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/423714#M94203</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2021-08-02T03:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: custom url category with non http and https port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/1243710#M125681</link>
      <description>&lt;P&gt;so, what is the solution to define a policy for wildcard domain not fqdn on ports other than https?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;something like this:&lt;/P&gt;
&lt;P&gt;-----------------------------&lt;/P&gt;
&lt;P&gt;Source Zone : trust&lt;/P&gt;
&lt;P&gt;Source user :- abc&lt;/P&gt;
&lt;P&gt;Destination Zone :- Untrust(internet)&lt;/P&gt;
&lt;P&gt;Destination :-&amp;nbsp; *.&amp;nbsp;ncra.tifr.res.in&lt;/P&gt;
&lt;P&gt;Port : 389,636&lt;/P&gt;
&lt;P&gt;Profile :- None&lt;/P&gt;
&lt;P&gt;Action :- Allow&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 12:39:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-url-category-with-non-http-and-https-port/m-p/1243710#M125681</guid>
      <dc:creator>S.Kaleem</dc:creator>
      <dc:date>2025-12-11T12:39:22Z</dc:date>
    </item>
  </channel>
</rss>

