Hello, Are you seeing this in URL filtering log???? thats not known behaviour.
You would generally put *.facebook.com under object -> security profile- > URL filtering -> block/allow
* means all the subdomains - e.g. chat.facebook.com.
Hope this helps.
I have one more question.
I set URL Filtering to allow only Facebook in allow list, and block category Social Network.
PAN should block all of Social Network, and allow only Facebook in the same time right?
But it still block Facebook.
about your first question for names like *.facebook.com, it appears when a website is using SSL. Because of encryption, PaloAlto cannot see the real URL that is asked by the client. So it will log certificate name instead.
If you want to see URLs inside a SSL encrypted session, you must configure PA SSL Decryption.
I tried on both, and it is not working. But after restart device, it is work.
This is all i tried with regular expression,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!