<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Categories vs URL Filtering in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-vs-url-filtering/m-p/433650#M95903</link>
    <description>&lt;P&gt;Multiple answers!&amp;nbsp; For clarity, I assume when you say URL category, you mean URL category in a security policy rule.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;"Recently we've found that traffic not within a URL category specified in a rule is being allowed."&amp;nbsp; Any subsequent security policy rule allowing web-browsing or ssl will allow the traffic.&amp;nbsp; Only traffic matching your category will match your rule.&amp;nbsp; The advantage to URL filtering is that the security policy rule will match all web-browsing or ssl traffic, and not look for a subsequent security policy rule match.&lt;/LI&gt;&lt;LI&gt;"Would using the same category within a URL filter differ than only having a category configured?"&amp;nbsp; Yes, because it can perform different functions for different categories.&lt;/LI&gt;&lt;LI&gt;"Is there a time to use categories only instead of a filter?"&amp;nbsp; The most common example is if you want to use the additional fields in the security policy rule.&amp;nbsp; For example, HR (source user) is allowed to go to YouTube for training videos.&lt;/LI&gt;&lt;LI&gt;"My concern in using a filter is that it will block traffic allowed by another filter further down the ruleset."&amp;nbsp; This is the preferred implementation of &lt;EM&gt;pre-defined&lt;/EM&gt; categories in URL filtering.&amp;nbsp; If you block a &lt;EM&gt;pre-defined&lt;/EM&gt; category, you want to block all URLs in the category even if they match other &lt;EM&gt;pre-defined&lt;/EM&gt; URL categories.&amp;nbsp; The entries above the pre-defined categories allow exceptions to this rule and the priority is from top down.&lt;/LI&gt;&lt;LI&gt;"Does it not defeat the purpose of a filter to only alert on a single category and the remaining ones are set to none or block?"&amp;nbsp; No.&amp;nbsp; Your URL filtering example allows for a flexible &lt;EM&gt;corporate&lt;/EM&gt; security policy and logging.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Sep 2021 22:54:11 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-09-13T22:54:11Z</dc:date>
    <item>
      <title>URL Categories vs URL Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-vs-url-filtering/m-p/432595#M95886</link>
      <description>&lt;P&gt;Multiple questions - Recently we've found that traffic not within a URL category specified in a rule is being allowed. The rule appears to be allowing the traffic as the session starts and ends with the action of allowed determined. Would using the same category within a URL filter differ than only having a category configured? It's my understanding that the only difference between the two is that the filter allows you to specify multiple categories and alert on them, whereas the URL category section does not allow for alerting and uses the action specified by the rule. We are using app-id on this rule. Is there a time to use categories only instead of a filter? My concern in using a filter is that it will block traffic allowed by another filter further down the ruleset. Does it not defeat the purpose of a filter to only alert on a single category and the remaining ones are set to none or block?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 14:37:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-vs-url-filtering/m-p/432595#M95886</guid>
      <dc:creator>CBeaver</dc:creator>
      <dc:date>2021-09-08T14:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categories vs URL Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-vs-url-filtering/m-p/433612#M95894</link>
      <description>&lt;P&gt;What most of my customers use this feature for is in the realm of zero trust. The URL category list allows to do things like write a rule at the top of the hierachy, block all web advertisements. But we can also specifically allow the sites users sign-in to.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;For example, they create EDLs of internal domains, or custom URL lists. Then they write a rule "internal-corp"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From users to internal app web browsing URL category internal URLs and that custom URL list has a credential theft setting of allow, since those are known good domains.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything else is set to alert at least, blocking just about everything from the profile perspective. This also allows you to configure the same profile behaviors for external apps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Submitting corp credentials to *.microsoftonline.com or something would be okay, assuming it's on your custom URL list, but you can block lots with categories, that you attach as a profile to those rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In general, it's a customization feature that allows you to get more specific if you choose.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 19:54:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-vs-url-filtering/m-p/433612#M95894</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-09-13T19:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categories vs URL Filtering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-vs-url-filtering/m-p/433650#M95903</link>
      <description>&lt;P&gt;Multiple answers!&amp;nbsp; For clarity, I assume when you say URL category, you mean URL category in a security policy rule.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;"Recently we've found that traffic not within a URL category specified in a rule is being allowed."&amp;nbsp; Any subsequent security policy rule allowing web-browsing or ssl will allow the traffic.&amp;nbsp; Only traffic matching your category will match your rule.&amp;nbsp; The advantage to URL filtering is that the security policy rule will match all web-browsing or ssl traffic, and not look for a subsequent security policy rule match.&lt;/LI&gt;&lt;LI&gt;"Would using the same category within a URL filter differ than only having a category configured?"&amp;nbsp; Yes, because it can perform different functions for different categories.&lt;/LI&gt;&lt;LI&gt;"Is there a time to use categories only instead of a filter?"&amp;nbsp; The most common example is if you want to use the additional fields in the security policy rule.&amp;nbsp; For example, HR (source user) is allowed to go to YouTube for training videos.&lt;/LI&gt;&lt;LI&gt;"My concern in using a filter is that it will block traffic allowed by another filter further down the ruleset."&amp;nbsp; This is the preferred implementation of &lt;EM&gt;pre-defined&lt;/EM&gt; categories in URL filtering.&amp;nbsp; If you block a &lt;EM&gt;pre-defined&lt;/EM&gt; category, you want to block all URLs in the category even if they match other &lt;EM&gt;pre-defined&lt;/EM&gt; URL categories.&amp;nbsp; The entries above the pre-defined categories allow exceptions to this rule and the priority is from top down.&lt;/LI&gt;&lt;LI&gt;"Does it not defeat the purpose of a filter to only alert on a single category and the remaining ones are set to none or block?"&amp;nbsp; No.&amp;nbsp; Your URL filtering example allows for a flexible &lt;EM&gt;corporate&lt;/EM&gt; security policy and logging.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 22:54:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-vs-url-filtering/m-p/433650#M95903</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-13T22:54:11Z</dc:date>
    </item>
  </channel>
</rss>

