<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow specific URL from being processed by data filter in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13032#M9549</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mckinzie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are looking to block a URL filtering category but allow a specific URL that belongs to that category, here is how you would do it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="facebook.PNG.png" class="jive-image" height="511" src="https://live.paloaltonetworks.com/legacyfs/online/9719_facebook.PNG.png" style="width: 747.2169811320755px; height: 511px;" width="747" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the following screenshot, social networking category is blocked but facebook.com is allowed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The order of precedence taken:&lt;/P&gt;&lt;OL start="1" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;Block list&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;Allow list&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;custom categories&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;pre-defined categories&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I understood your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Nov 2013 17:02:26 GMT</pubDate>
    <dc:creator>kadak</dc:creator>
    <dc:date>2013-11-12T17:02:26Z</dc:date>
    <item>
      <title>Allow specific URL from being processed by data filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13031#M9548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this possible?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 16:49:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13031#M9548</guid>
      <dc:creator>kmckinzie</dc:creator>
      <dc:date>2013-11-12T16:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Allow specific URL from being processed by data filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13032#M9549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mckinzie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are looking to block a URL filtering category but allow a specific URL that belongs to that category, here is how you would do it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="facebook.PNG.png" class="jive-image" height="511" src="https://live.paloaltonetworks.com/legacyfs/online/9719_facebook.PNG.png" style="width: 747.2169811320755px; height: 511px;" width="747" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the following screenshot, social networking category is blocked but facebook.com is allowed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The order of precedence taken:&lt;/P&gt;&lt;OL start="1" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;Block list&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;Allow list&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;custom categories&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;pre-defined categories&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I understood your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 17:02:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13032#M9549</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-12T17:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Allow specific URL from being processed by data filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13033#M9550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The response is not what I am looking for. It is more toward the data filtering side. The data filtering probably needs to be configured better. As fast fix without turning data filtering completely off for SSN, I was wanting to bypass a specific supplier URL that has data in the form of SSNs but are not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 19:14:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13033#M9550</guid>
      <dc:creator>kmckinzie</dc:creator>
      <dc:date>2013-11-12T19:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: Allow specific URL from being processed by data filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13034#M9551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Mckinzie&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now that I have understood your concern, as far as creating a URL exception for a data filtering profile is concerned, PAN firewall currently doesn't have the capability to do that. However, what you can can try is create another security rule -- without the data-filtering profile applied to it and a URL filtering profile with that specific URL mentioned in the allow list and place it on top of the existing rule which has the data-filtering profile. In that way, whenever the traffic concerned with that specific URL hits the firewall, it will only match a new rule which doesn't have the data-filtering profile. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR, the regex pattern itself needs to re-configured to avoid those SSN false-positives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know what do you think about the workaround.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On another note, if you think this feature would be valuable addition, you can submit a feature request through your account's SE to our development team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;BR /&gt;Kunal Adak.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 19:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13034#M9551</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-12T19:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Allow specific URL from being processed by data filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13035#M9552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay thanks. I will modify security rules with a hierarchy of the supplier URL filter on top.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 20:03:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-specific-url-from-being-processed-by-data-filter/m-p/13035#M9552</guid>
      <dc:creator>kmckinzie</dc:creator>
      <dc:date>2013-11-12T20:03:39Z</dc:date>
    </item>
  </channel>
</rss>

