<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fortigate Minemeld URL feed injestion issue - outgoing URL connections blocked by Minemeld feed policy on Fortigate Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fortigate-minemeld-url-feed-injestion-issue-outgoing-url/m-p/402720#M95278</link>
    <description>&lt;P&gt;Good afternoon,&lt;/P&gt;
&lt;P&gt;we've noticed a strange issue on a client firewall that injests URL IoCs from our Minemeld instance into an outbound block policy.&lt;/P&gt;
&lt;P&gt;Specifically it seems that the Firewall Minemeld Policy is blocking outgoing URLs connections that are not actually present inside the Minemeld URL output feed. We're investigating the issue as it seems a firewall injestion problem and we will keep this discussion updated.&lt;/P&gt;
&lt;P&gt;Further details are:&lt;/P&gt;
&lt;P&gt;- Miner &amp;amp; Output nodes are using the following feed: &lt;SPAN&gt;&lt;A href="https://openphish.com/feed.txt" target="_blank"&gt;https://openphish.com/feed.txt&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- the URLs blocked by the firewall policy: &lt;A href="http://www.google.com/" target="_blank"&gt;www.google.com,&lt;/A&gt;&amp;nbsp;&lt;A href="http://secure-web.cisco.com/1krLs7fcULJrCuXr-rp2B6NJgBrkfD2V0QsW6psBQmZaX6eb27u0n3ohTycBDuMflpE1Y4j4Eda4b12VqwKHGW8bPRRPITsKZ7pYmBni_cCDXM9t3RQUbcXJq_ma2qJh6iwJ0ZRQUqwG-kOzp7YEC5xfEIoqgyvslma_zLIjjJ_471UgGdTTvVFiRD3T1nVFvv9RdZz_6NA46kiRIlFgWJAIUzW-_ve0FRQSxfMqJjQ2bVFjiHgrp_GfgHhbABfkBhb621y7nhs2tljiBKx2YRB1Dg0DxK6HsPzmNP-5zwEChaPH39BAa0H_05iPSERNp/http%3A%2F%2Fwww.cprsystem.it%2F" target="_blank"&gt;www.cprsystem.it/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Firewall vendor: Fortigate (i'll ask the version)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you maybe have any additional info or suggestion please comment.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;V.E.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Apr 2021 13:58:06 GMT</pubDate>
    <dc:creator>VCiverra</dc:creator>
    <dc:date>2021-04-28T13:58:06Z</dc:date>
    <item>
      <title>Fortigate Minemeld URL feed injestion issue - outgoing URL connections blocked by Minemeld feed policy on Fortigate Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fortigate-minemeld-url-feed-injestion-issue-outgoing-url/m-p/402720#M95278</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;
&lt;P&gt;we've noticed a strange issue on a client firewall that injests URL IoCs from our Minemeld instance into an outbound block policy.&lt;/P&gt;
&lt;P&gt;Specifically it seems that the Firewall Minemeld Policy is blocking outgoing URLs connections that are not actually present inside the Minemeld URL output feed. We're investigating the issue as it seems a firewall injestion problem and we will keep this discussion updated.&lt;/P&gt;
&lt;P&gt;Further details are:&lt;/P&gt;
&lt;P&gt;- Miner &amp;amp; Output nodes are using the following feed: &lt;SPAN&gt;&lt;A href="https://openphish.com/feed.txt" target="_blank"&gt;https://openphish.com/feed.txt&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- the URLs blocked by the firewall policy: &lt;A href="http://www.google.com/" target="_blank"&gt;www.google.com,&lt;/A&gt;&amp;nbsp;&lt;A href="http://secure-web.cisco.com/1krLs7fcULJrCuXr-rp2B6NJgBrkfD2V0QsW6psBQmZaX6eb27u0n3ohTycBDuMflpE1Y4j4Eda4b12VqwKHGW8bPRRPITsKZ7pYmBni_cCDXM9t3RQUbcXJq_ma2qJh6iwJ0ZRQUqwG-kOzp7YEC5xfEIoqgyvslma_zLIjjJ_471UgGdTTvVFiRD3T1nVFvv9RdZz_6NA46kiRIlFgWJAIUzW-_ve0FRQSxfMqJjQ2bVFjiHgrp_GfgHhbABfkBhb621y7nhs2tljiBKx2YRB1Dg0DxK6HsPzmNP-5zwEChaPH39BAa0H_05iPSERNp/http%3A%2F%2Fwww.cprsystem.it%2F" target="_blank"&gt;www.cprsystem.it/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Firewall vendor: Fortigate (i'll ask the version)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you maybe have any additional info or suggestion please comment.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;V.E.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 13:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fortigate-minemeld-url-feed-injestion-issue-outgoing-url/m-p/402720#M95278</guid>
      <dc:creator>VCiverra</dc:creator>
      <dc:date>2021-04-28T13:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate Minemeld URL feed injestion issue - outgoing URL connections blocked by Minemeld feed policy on Fortigate Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fortigate-minemeld-url-feed-injestion-issue-outgoing-url/m-p/403179#M95279</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158751"&gt;@VCiverra&lt;/a&gt;&amp;nbsp;I am sorry but I don't know much about Fortigate. Maybe someone in the community can help you.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 15:04:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fortigate-minemeld-url-feed-injestion-issue-outgoing-url/m-p/403179#M95279</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2021-04-28T15:04:04Z</dc:date>
    </item>
  </channel>
</rss>

