<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does URL Filtering Profile with a custom URL Category assigned require the same custom URL category assigned in a security rule to work? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-url-filtering-profile-with-a-custom-url-category/m-p/420376#M93868</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pardon me for the lengthy title.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the layout of what I am working with:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I am currently running PAN-3020 on PAN-OS 9.0.13&lt;/LI&gt;&lt;LI&gt;I do not have a URL filtering licence&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;I do not yet do decryption (long story).&lt;/LI&gt;&lt;LI&gt;Security rules are any/any for testing this.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been tinkering with custom URL categories and filtering profiles. I have got what I intended to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am confused by the behaviour of the firewall and further lost amongst content all over the internet, especially when it comes to URL filtering without a licence. Was hoping someone could help clarify it out for me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;===========&lt;BR /&gt;Scenario 1&lt;/P&gt;&lt;P&gt;Security policy rule A:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule with an action of allow&lt;/LI&gt;&lt;LI&gt;URL filtering profile assigned which also allows a good custom URL category&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Security policy rule B:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule with an action of allow&lt;/LI&gt;&lt;LI&gt;URL filtering profile assigned which blocks a bad custom URL category&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No traffic will match security policy rules A or B. The only time traffic match either of these two rules is when I specify a URL category under the&lt;EM&gt; Service/URL Category&lt;/EM&gt; tab for security policy rule A.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenario 2&lt;/P&gt;&lt;P&gt;Security policy rule A:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule with an action of allow&lt;/LI&gt;&lt;LI&gt;Custom URL category assigned to "services/URL Category" tab (found within the security policy rule),&lt;/LI&gt;&lt;LI&gt;URL filtering profile assigned that allows a good custom URL cateogry&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Security policy rule B =&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule with an action of allow&lt;/LI&gt;&lt;LI&gt;Assigned URL filtering profile that blocks a bad custom URL category&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;URL traffic not matching any URLs specified rule A is now blocked.&lt;/P&gt;&lt;P&gt;===========&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I can't get my head around is why isn't it enough to simply use a security rule and a relative filtering profile that references the good custom URL category?&lt;BR /&gt;Why when I don't specify the URL category, no traffic matches even though the filtering profile is there?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Apologies for my ignorance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Martins&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jul 2021 16:10:13 GMT</pubDate>
    <dc:creator>mr_almeida</dc:creator>
    <dc:date>2021-07-19T16:10:13Z</dc:date>
    <item>
      <title>Why does URL Filtering Profile with a custom URL Category assigned require the same custom URL category assigned in a security rule to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-url-filtering-profile-with-a-custom-url-category/m-p/420376#M93868</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pardon me for the lengthy title.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the layout of what I am working with:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I am currently running PAN-3020 on PAN-OS 9.0.13&lt;/LI&gt;&lt;LI&gt;I do not have a URL filtering licence&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;I do not yet do decryption (long story).&lt;/LI&gt;&lt;LI&gt;Security rules are any/any for testing this.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been tinkering with custom URL categories and filtering profiles. I have got what I intended to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am confused by the behaviour of the firewall and further lost amongst content all over the internet, especially when it comes to URL filtering without a licence. Was hoping someone could help clarify it out for me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;===========&lt;BR /&gt;Scenario 1&lt;/P&gt;&lt;P&gt;Security policy rule A:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule with an action of allow&lt;/LI&gt;&lt;LI&gt;URL filtering profile assigned which also allows a good custom URL category&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Security policy rule B:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule with an action of allow&lt;/LI&gt;&lt;LI&gt;URL filtering profile assigned which blocks a bad custom URL category&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No traffic will match security policy rules A or B. The only time traffic match either of these two rules is when I specify a URL category under the&lt;EM&gt; Service/URL Category&lt;/EM&gt; tab for security policy rule A.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenario 2&lt;/P&gt;&lt;P&gt;Security policy rule A:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule with an action of allow&lt;/LI&gt;&lt;LI&gt;Custom URL category assigned to "services/URL Category" tab (found within the security policy rule),&lt;/LI&gt;&lt;LI&gt;URL filtering profile assigned that allows a good custom URL cateogry&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Security policy rule B =&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule with an action of allow&lt;/LI&gt;&lt;LI&gt;Assigned URL filtering profile that blocks a bad custom URL category&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;URL traffic not matching any URLs specified rule A is now blocked.&lt;/P&gt;&lt;P&gt;===========&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I can't get my head around is why isn't it enough to simply use a security rule and a relative filtering profile that references the good custom URL category?&lt;BR /&gt;Why when I don't specify the URL category, no traffic matches even though the filtering profile is there?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Apologies for my ignorance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Martins&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 16:10:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-url-filtering-profile-with-a-custom-url-category/m-p/420376#M93868</guid>
      <dc:creator>mr_almeida</dc:creator>
      <dc:date>2021-07-19T16:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why does URL Filtering Profile with a custom URL Category assigned require the same custom URL category assigned in a security rule to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-url-filtering-profile-with-a-custom-url-category/m-p/421447#M93958</link>
      <description>&lt;P&gt;Url categories in the services tab behave somewhat like an FQDN object, while urls added in the url filtering profile are only applied at layer7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the former causing an "traffic log" (l4) allow or drop, with the latter causing a response page with a traffic allow for both drop and allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 17:59:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-url-filtering-profile-with-a-custom-url-category/m-p/421447#M93958</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-07-22T17:59:47Z</dc:date>
    </item>
  </channel>
</rss>

