URL Filtering different with browser and application

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

URL Filtering different with browser and application

L3 Networker

Hi

 

We have a server, from where the user wants to go to, for example, abc.xyz.com.

The certificate from the website xyz.com has a CN *.xyz.com.

 

We dont have decryption for URL Filtering. In the URL Filtering category, we have allowed abc.xyz.com.

The user on the server wants to use an application which initiates a connection to abc.xyz.com.

Now,

When the user opens a browser and goes to abc.xyz.com, then the connection is allowed as the firewall sees the URL as abc.xyz.com. 

When the user uses his application, the the firewall sees the request to *.xyz.com and blocks it. 

If we allow *.xyz.com then the application works.

 

Anyone have same experience? Any workaround without decryption?

 

BR,

RJ

3 REPLIES 3

Cyber Elite
Cyber Elite

@rjdahav163,

You need to do a wireshark or fiddler capture and see what URLs are actually being called by the application that the user is attempting to use. Fiddler is probably the best solution. IF you can't access the users machine directly for whatever reason create a specific policy for the user and assign a URL profile that has the action of Alert for all categories so that every visited URL will be logged by the firewall. 

If you look at those logs I'm sure you'll fine additional URLs that you aren't allowing in your URL Filtering profile. 

@BPry

 

I tried your solution with the Profile and Alert as action. In the logs we see the URL as  -->    *.xyz.com/  

 

Dont know from where the / is coming? Really confused.

 

BR,

RJ

*.xyz.com comes probably from name on the certificate.

As you are not decrypting traffic then Palo can't see what comes after *.xyz.com/ and URL is logged with / at the end.

You are good if you whitelist *.xyz.com

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1977 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!