04-13-2021 06:40 AM
I have created a custom URL category for a site and have a security policy to allow specific applications to that category but the results are inconsistent and when I review the log, when the traffic was successful the URL Category shows as the custom category and whenever it fails, it shows the URL category as a default PAN category (in this case computer-and-internet-info) despite the destination IP addresses being the same. I can see the traffic shows as decrypted, it shows the expected application, ports, etc... it's just the resulting category that seems to change.
When I do security policy test, the proper rule is returned but live traffic it fails.
Is there something obvious I am missing?
04-13-2021 12:47 PM
I would also recommend taking a screen shot of the denied traffic logs, and comparing it to the security policy its supposed to hit.
04-13-2021 01:40 PM
No wildcards or escape characters. It's a static FQDN in the format of subdomain2.subdomain1.domain.com.
04-13-2021 01:49 PM
I did this comparison before the post and it's how I saw that the URL category is different when it's blocked than when it is allowed.
So to use MS Teams as example, say the site is media.teams.microsoft.com. This URL is added to a custom URL category. Then in the security policy the application is ms-teams-downloading and ms-teams-uploading, ports are tcp 80/443, URL category is the custom URL category object and I have some basic profiles in the actions tab.
When traffic goes to the IP for media.teams.microsoft.com and the application is ms-teams-uploading, traffic is allowed and the log shows the category as the custom URL object. When traffic goes to the IP for media.teams.microsoft.com and the application is ms-teams-downloading, the traffic is blocked and the category is the default PAN computer-and-internet-info.
04-14-2021 01:27 AM
You need to allow this category computer-and-internet-info as well to resolve the issue.
04-14-2021 06:10 AM
Adding computer-and-internet-info as an allowed category kind of defeats the purpose of the custom category, doesn't it? And why does the custom category show for uploading but not downloading?
04-15-2021 05:19 AM
Not yet... currently it is 8.1.17. I'm in the middle of updating to 9.1.8 company wide though, so your post doesn't fill me with hope.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!