- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-24-2013 08:09 AM
I saw this line in an article about Dynamic Block Lists.
"as our threat team identifies malware, they automatically take any URL or IP associated with that threat and will include it as part of the PAN-DB URL filtering database. "
Does this mean that the PAN-DB contains all the IP's that the URL's resolve to? I would not think so since that one IP may have legitimate URL/URI's associated with it. Can someone clarify?
Thanks,
Jim
08-24-2013 10:32 AM
Hello Jim,
URL categorization takes advantage of a URL filtering database on the firewall that lists the most popular URLs and other URLs for malicious categories. The URL filtering database may be able to resolve requests that the local database is unable to categorize. The default is enabled when using the BrightCloud database. When using the PAN-DB, this option is enabled by default and is not configurable. PAN-DB will not contain all the IP's that the URL's resolve to.
To configure the system response when a URL remains unresolved after a 5 second timeout period, use the Category and Action settings in this window. Select the action for the category “Not resolved URL.
Thanks
08-24-2013 03:47 PM
The statement is TRUE only for malware URLs /IP addresses identified by the PA Threat Research Team.
PAN-DB does not contain all the IPs associated with a URL.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!