Allow traffic to specific URL - Best practices

Reply
Highlighted
L3 Networker

Allow traffic to specific URL - Best practices

Dears,

I have 2 PA2020 implemented working as webfilter only. (virtual wire feature)

I need to implement a rule which will permit any user to access the website www.adpweb.com.br anytime...

What I did:

Rule at first position

ScreenShot346.jpg

source: any user, any zone,

destination: any IP, any zone

URL: I created a specific URL Category

ScreenShot345.jpg

I see that many others traffics are passing using this rule....

Question:

How is the best practice to implement this rule?

All users here, doesnt matter the profile or department should be able to access this website...

After this rule all other rules are already implemented to filter/permit traffic

Logs showing many kinds of traffic parring thru this rule:

ScreenShot347.jpg

Thanks in advance!!


Accepted Solutions
Highlighted

I don't know why the Traffic hits your first Rule.

Normally i should not match this Rule if the URL Category does not apply.

But you can modify your Rule that the Destination Address FQDN matches to your Server.

Something like this:

For the URL Category there is more debugging necessary.

You can activate the visibility of the URL Category column :

Regards

Marco

View solution in original post


All Replies
Highlighted

I don't know why the Traffic hits your first Rule.

Normally i should not match this Rule if the URL Category does not apply.

But you can modify your Rule that the Destination Address FQDN matches to your Server.

Something like this:

For the URL Category there is more debugging necessary.

You can activate the visibility of the URL Category column :

Regards

Marco

View solution in original post

Highlighted
L3 Networker

Hey Marco!

That worked very well!!!

Now I see only that IP address passing thru that rule...

Danke schön!!!!

Fabio

Highlighted
L6 Presenter

I think the problem is that this rule is "appid:any, service:any" which gives that the url category stuff is only valid for web-based appids. Meaning if oracle and other non-web-based flows arrives they wont be checked for the url category.

The proper setup of this rule should be:

appid:web-browsing

service:application-default (or if possible set it manually to TCP80 or whatever proto/port this server uses)

url-category: allow only "www.adpweb.com.br".

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!