- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-25-2024 01:51 AM
Hello everyone,
my name is Phil and I am in charge of the network structure in a municipal utility with 2 other people. We have 2 PA-3220s with software version 11.0.2-h2 and several PA-400s in use.
We are faced with the following problem:
We want to block the entire Internet for one user (Active Directory is connected to Palo Alto), except for 2 domains
- https://www.wetter.com/
- https://www.radio.de/
We were able to help ourselves with the following KB entry:
https://live.paloaltonetworks.com/t5/general-topics/how-do-i-block-all-url-traffic-but-a-select-few/...
This works so far, all websites are blocked except these two. However, we are faced with the following problem: the URLs use embedded links that point to a wide variety of pages, but these are of course blocked by the firewall.
Now to the question, do I have the possibility to unblock everything that is embedded on the original page without entering all links manually?
The required links change and would have to be checked again and again, which would not be profitable in this case.
Perhaps someone has already faced this problem and has an idea?
Best regards
Phil
03-25-2024 12:08 PM
I am not aware of any option in the PA that will allow you to automatically except URLs/FQDNs within an allowed website, but keep those blocked when referenced from outside the website.
With the way many current websites include resources from all different sources, allowing to very restricted web access that fully loads can be difficult. You often have to allow broader access to CDN/scripting domains to get things to fully render. Not really shown in the article you referenced, you can use regex filters (limited syntax) in your URL Categories for filtering/matching.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oM79CAE
Also important to remember order of precedence in URL filtering: block before allow, custom before built-in. So anything blocked in a custom regex will still be blocked, even when there is a more specific allow rule.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC
03-27-2024 11:18 PM
Thank you for your detailed post and the corresponding link.
We wonder how other companies solve this, or whether this situation is outdated in times of smartphones and unlimited data volume 😉
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!