09-04-2013 12:55 AM
What's wrong with the URL filtering and logging of the PaloAlto FW? We have many URL logs like '%16%03%01/' when users visit SSL websites.
Is URL detection for SSL websites broken?
Are there other users who have this problems?
We are not 100% sure but it seems this log happens only when Internet Explorer 8 is used. But still investigating
Regards,
O. Bor
09-04-2013 01:08 AM
Yes, there is some issue with the version 390. Engineering is currently working on it. The issue is that the SSL sites are being categorized as "private-ip-addresses" after upgrading the content to version 390.
Issue reported as:- "SSL sites are being categorized as 'private-ip-addresses' after upgrading content to version 390". Only IE8 seems to be affected.... Chrome, Firefox and IE9 seem to be not be affected. As of now, the workaround would be to revert to content version 389/ update to content version 391 or do not block 'private-ip-address' category.
Thanks
09-04-2013 01:00 AM
What is the Apps and threat content version on the firewall ? Is it 390 ?
09-04-2013 01:06 AM
There is a known issue in version 390. I would recommend you to upgrade to the new version 391 which was released few hours ago. That should resolve.
09-04-2013 01:08 AM
Yes, there is some issue with the version 390. Engineering is currently working on it. The issue is that the SSL sites are being categorized as "private-ip-addresses" after upgrading the content to version 390.
Issue reported as:- "SSL sites are being categorized as 'private-ip-addresses' after upgrading content to version 390". Only IE8 seems to be affected.... Chrome, Firefox and IE9 seem to be not be affected. As of now, the workaround would be to revert to content version 389/ update to content version 391 or do not block 'private-ip-address' category.
Thanks
09-04-2013 01:20 AM
I was aware of the problems with 390 and a few hours ago we have upgraded to 391 and we have still these url logs. Thats why i posted this to ask if more people have the same issue. So it seems that 391 is still having this issue.
Thanks for all responses.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!