<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Category traffic flow issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397572#M91487</link>
    <description>&lt;P&gt;What escape / end characters are you using in your formatting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5982#M4351" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Apr 2021 19:23:35 GMT</pubDate>
    <dc:creator>LAYER_8</dc:creator>
    <dc:date>2021-04-13T19:23:35Z</dc:date>
    <item>
      <title>Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397500#M91482</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have created a custom URL category for a site and have a security policy to allow specific applications to that category but the results are inconsistent and when I review the log, when the traffic was successful the URL Category shows as the custom category and whenever it fails, it shows the URL category as a default PAN category (in this case computer-and-internet-info) despite the destination IP addresses being the same.&amp;nbsp; I can see the traffic shows as decrypted, it shows the expected application, ports, etc... it's just the resulting category that seems to change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;When I do security policy test, the proper rule is returned but live traffic it fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there something obvious I am missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 13:40:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397500#M91482</guid>
      <dc:creator>EmptySet</dc:creator>
      <dc:date>2021-04-13T13:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397572#M91487</link>
      <description>&lt;P&gt;What escape / end characters are you using in your formatting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/url-filtering-wildcards/m-p/5982#M4351" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 19:23:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397572#M91487</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-04-13T19:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397626#M91488</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would also recommend taking a screen shot of the denied traffic logs, and comparing it to the security policy its supposed to hit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 19:47:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397626#M91488</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-04-13T19:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397823#M91492</link>
      <description>&lt;P&gt;No wildcards or escape characters.&amp;nbsp; It's a static FQDN in the format of subdomain2.subdomain1.domain.com.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 20:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397823#M91492</guid>
      <dc:creator>EmptySet</dc:creator>
      <dc:date>2021-04-13T20:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397826#M91493</link>
      <description>&lt;P&gt;I did this comparison before the post and it's how I saw that the URL category is different when it's blocked than when it is allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to use MS Teams as example, say the site is media.teams.microsoft.com.&amp;nbsp; This URL is added to a custom URL category.&amp;nbsp; Then in the security policy the application is ms-teams-downloading and ms-teams-uploading, ports are tcp 80/443, URL category is the custom URL category object and I have some basic profiles in the actions tab.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When traffic goes to the IP for media.teams.microsoft.com and the application is ms-teams-uploading, traffic is allowed and the log shows the category as the custom URL object.&amp;nbsp; When traffic goes to the IP for media.teams.microsoft.com and the application is ms-teams-downloading, the traffic is blocked and the category is the default PAN computer-and-internet-info.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 20:49:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397826#M91493</guid>
      <dc:creator>EmptySet</dc:creator>
      <dc:date>2021-04-13T20:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397999#M91500</link>
      <description>&lt;P&gt;You need to allow this category&amp;nbsp;&lt;STRONG&gt;computer-and-internet-info&amp;nbsp;&lt;/STRONG&gt;as well to resolve the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 08:27:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/397999#M91500</guid>
      <dc:creator>Avinash1</dc:creator>
      <dc:date>2021-04-14T08:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/398041#M91503</link>
      <description>&lt;P&gt;Adding computer-and-internet-info as an allowed category kind of defeats the purpose of the custom category, doesn't it?&amp;nbsp; And why does the custom category show for uploading but not downloading?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 13:10:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/398041#M91503</guid>
      <dc:creator>EmptySet</dc:creator>
      <dc:date>2021-04-14T13:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/398286#M91510</link>
      <description>&lt;P&gt;It wouldn't happen to be version 9.1.8 or similar, would it? If so, we're fighting with the exact same issue.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 22:04:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/398286#M91510</guid>
      <dc:creator>EricPrehn</dc:creator>
      <dc:date>2021-04-14T22:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Category traffic flow issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/398415#M91519</link>
      <description>&lt;P&gt;Not yet... currently it is 8.1.17.&amp;nbsp; I'm in the middle of updating to 9.1.8 company wide though, so your post doesn't fill me with hope.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 12:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-category-traffic-flow-issue/m-p/398415#M91519</guid>
      <dc:creator>EmptySet</dc:creator>
      <dc:date>2021-04-15T12:19:31Z</dc:date>
    </item>
  </channel>
</rss>

