Block HTTP/HTTPS access via IP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Block HTTP/HTTPS access via IP

L0 Member

Hello.

 

I would like to block access to my site (http/https) when it is made via IP.

I want to only allow access made by name.

 

Ex.: www.mysite.com <=> 1.2.3.4

 

https://1.2.3.4 => deny

https://www.mysite.com => allow

 

PA-access.by.name.jpg

 

Is that possible with Palo Alto?

Thanks.

1 REPLY 1

Cyber Elite
Cyber Elite

@Robynson,

Couple ways off hand:

 

* Custom URL Category assigned to the security policy allowing external access - This is by far the most effective way to accomplish what you're attempting to do since you're just trying to do it for your own website(s). 

 

* Blocking the unknown category - Same thing really, but you would assign a URL filtering profile on the external access entry that blocks medium-risk and unknown categories. You'd have to verify what effect this would have with your own URL logs, but direct IP access is always going to be labelled as medium-risk,unknown by the firewall. Blocking access to those would block direct IP access, but could cause issues depending on how your website(s) are actually categorized.


The one thing to be mindful of here is that you'd want to ensure that you actually look through your logs and create a separate URL Filtering profile to assign if you go with that second option. GlobalProtect's hip-check is sent directly to the IP address instead of the FQDN, so you don't want to just block medium-risk and unknown categories on the profile you use for all of your external access rules. 

  • 1858 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!