Custom URL Categories - ending tokens

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Custom URL Categories - ending tokens

L3 Networker

Let's say we want to match a domain in a custom URL category or EDL, including all sub-domains. While most people would expect "" to do the job, in a PAN-OS this would only match and not To achieve the result we must include:


I can live with that... however in PAN-OS 10 admins are now served a recommendation to use an ending token such as ./?&=;+ when building custom URL categories in the web UI, and if such a token is not present the condition may match more than intended. The example provided for "" (note the dot) will match and a suggestion is given to enter the domain as '' (again note the dot).


I have two questions regarding this statement

1. Is the dot at the end of these statements a mistake? I'd expect "" to match but "" should only match any path on beginning with a dot (e.g. ./index.html).

2. If so, does that mean all my implementations with "" will be matching phishing domains like ""? And why doesn't the same logic apply to subdomains i.e. "" matches "" as well as just "".

3. I'm sure different people wrote these parts of the UI, because in the Custom URL Category box recommends just using a forward slash (no dot).

4. Clearly I cannot count


Cyber Elite
Cyber Elite

i think that last dot is a mistake


if you add a domain '' it could also match (but not because you didn't 'terminate' after your tld and it simply matches characters in a token (anything between dots is a token). a  dot at the end signifies there must be a dot followed by another token, so that would force some sort of tailing fqdn bit ( = ) a slash at the end 'ends' the fqdn part/token as to prevent phishing and 'happy mistakes' ( will still match and but no longer 



Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!