Allow one URL out of many sharing an IP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Allow one URL out of many sharing an IP

L0 Member

We're faced with a bit of a challenge. We blocked a GoDaddy-Hosting IP for sending malicious traffic to our campus. Faculty later complained that a site they rely on is hosted with the same IP. I've attempted many different configurations with IP filtering, URL whitelisting etc, but can't quite arrive at a simple working solution (Plan B is blacklisting every other known URL that shares the IP... not elegant). We'd like to block traffic to and from that IP and campus, but allow connections to be made from within campus to the one legitimate URL.

 

 

1 accepted solution

Accepted Solutions

allowing access to the FQDN (through an FQDN address object) will open access to the IP rather than the URL. 

 

You can resolve this by creating a custom category containing the url, then use that category in the security policy's service/URLcategory tab, then a second rule below that, that drops all other traffic to that IP

 

2015-11-09_09-22-21.png

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

So your users need to access one website on this bad IP?

Why don't you create rule to allow traffic to that FQDN and then second rule below that to block any traffic towards that bad IP?

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

allowing access to the FQDN (through an FQDN address object) will open access to the IP rather than the URL. 

 

You can resolve this by creating a custom category containing the url, then use that category in the security policy's service/URLcategory tab, then a second rule below that, that drops all other traffic to that IP

 

2015-11-09_09-22-21.png

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 1908 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!