<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict internet access? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12922#M9468</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Follow jdavis advice and create a _new_ URL filter profile. Then use this in a new firewall policy that targets that specific network host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just make sure that the new policy is above any other policy that allow web browsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//Marcus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Aug 2011 12:46:40 GMT</pubDate>
    <dc:creator>admin3r</dc:creator>
    <dc:date>2011-08-11T12:46:40Z</dc:date>
    <item>
      <title>Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12917#M9463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Is there a way to restrict internet access to a device so that it can only get out to a particular website?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 18:08:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12917#M9463</guid>
      <dc:creator>lcepeda</dc:creator>
      <dc:date>2011-08-10T18:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12918#M9464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can setup a URL filterig profile with allowed sites and block the rest.&lt;/P&gt;&lt;P&gt;Security rule for the source can be setup trust to untrust allow and apply the security profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The security profile will scan the traffic after it matches the allow/deny condition and will allow only sites allowed. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 03:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12918#M9464</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2011-08-11T03:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12919#M9465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's just the thing.&amp;nbsp; I don't find the place where I can add URL addresses.&amp;nbsp; Perhaps I'm not in the right place. I'm looking under policies , new, security policy I just want to allow this host to get out to one site on the web.&amp;nbsp; Thanks, Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 03:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12919#M9465</guid>
      <dc:creator>lcepeda</dc:creator>
      <dc:date>2011-08-11T03:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12920#M9466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You'll find what you're looking for under Objects tab &amp;gt; Security Profiles section &amp;gt; URL Filtering link.&amp;nbsp; Either edit an existing profile or create a new one.&amp;nbsp; You'll find a Block List and an Allow List.&amp;nbsp; You'll need to commit the configuration change for it to take effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jared &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 04:29:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12920#M9466</guid>
      <dc:creator>jdavis</dc:creator>
      <dc:date>2011-08-11T04:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12921#M9467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Jared,&lt;/P&gt;&lt;P&gt;thanks for pointing me in the right direction but I'm affraid what I do there will affect everyone.&amp;nbsp; I just need to restrict a single host on the network to be able to get out only to one site.&amp;nbsp; I dont want to enforce that on everyone.&amp;nbsp; I dont see a way to target that list from anywhere else.&lt;/P&gt;&lt;P&gt;any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Leo &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 12:37:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12921#M9467</guid>
      <dc:creator>lcepeda</dc:creator>
      <dc:date>2011-08-11T12:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12922#M9468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Follow jdavis advice and create a _new_ URL filter profile. Then use this in a new firewall policy that targets that specific network host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just make sure that the new policy is above any other policy that allow web browsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//Marcus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 12:46:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12922#M9468</guid>
      <dc:creator>admin3r</dc:creator>
      <dc:date>2011-08-11T12:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12923#M9469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Leo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try creating a new URL filtering profile that will only be used to control traffic from your single host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any changes made in this new profile will not affect users of other profiles. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enter the URL you want to allow in the allow list and block the rest.&amp;nbsp; Then in your security policy, add a rule to apply your new URL filtering profile to just traffic originating from your single host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 12:52:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12923#M9469</guid>
      <dc:creator>DavePalo</dc:creator>
      <dc:date>2011-08-11T12:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12924#M9470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys, I had neglected to select "profiles" from within the actions tab.&amp;nbsp; That's why I didn't see the url filter I created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will now commit this policy and cross my fingers that it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm now wondering if I need to create another filter that blocks everything and they apply both to the host so that only the site I specified in allow will work.&amp;nbsp; We'll see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 12:54:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12924#M9470</guid>
      <dc:creator>lcepeda</dc:creator>
      <dc:date>2011-08-11T12:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12925#M9471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Leo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to provide you mode details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Allow list: you allow any URLs on the list without logging&lt;/P&gt;&lt;P&gt;2. Block List: by default you are blocking URLs on the list with logging&lt;/P&gt;&lt;P&gt;3. Category: you can choose to alert/block/allow/continue/overide any URL access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see category gives you more option on details. It maybe better for you to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. go to object-&amp;gt;custom URL category&lt;/P&gt;&lt;P&gt;2. manual input the list of URL you want to allow&lt;/P&gt;&lt;P&gt;3. go back to the policy to create a URL profile&lt;/P&gt;&lt;P&gt;4. keep the whitelist and blocklist blank&lt;/P&gt;&lt;P&gt;5. on the right hand side set all the action to be block&lt;/P&gt;&lt;P&gt;6. on the right hand side find out the custom category you have just created (there will be * at the end of the category name to indicate that is a custom category)&lt;/P&gt;&lt;P&gt;7. change the action for this specific the custom category. E.g if you just want to allow them without logging choose allow; if you want to allow them with logging choose alert; if you want to provide a warning page before you allow them choose continue.&lt;/P&gt;&lt;P&gt;8. commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you are using category to control the access, and what you need to do is to update the custom category from object page time to time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 15:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12925#M9471</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-11T15:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict internet access?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12926#M9472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the feedback.&amp;nbsp; I actually tried using the category list and blocked all of them.&lt;/P&gt;&lt;P&gt;All I want is access to one site.&amp;nbsp; Unfortunately by doing it this way sub-pages within the allowed website fail to load properly.&amp;nbsp; For example I tested with allowing *.cnn.com/* but the only page that opens is the home page.&amp;nbsp; All other subpages within the cnn.com website appear as broken links.&lt;/P&gt;&lt;P&gt;And yes all other sites are blocked and it is displayed in the host browser.&amp;nbsp; So that's pretty cool.&amp;nbsp; I'll keep messing with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 15:27:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-internet-access/m-p/12926#M9472</guid>
      <dc:creator>lcepeda</dc:creator>
      <dc:date>2011-08-11T15:27:49Z</dc:date>
    </item>
  </channel>
</rss>

