- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-27-2024 08:37 AM
Hello,
IP address 74.102.229.126 is being blocked by Palo Alto's Malicious IP Feeds Inbound rule. However this is a network that should be allowed on customer s company.
We cannot see a way of submitting an IP address to whitelist.
on below link we have:
https://urlfiltering.paloaltonetworks.com/query/
URL: 74.102.229.126
Categories: Unknown
Risk Level: Medium-Risk
Category: Unknown
Description: Sites that have not yet been identified by URL Filtering. If availability is critical to your business and you must allow the traffic, alert on unknown sites, apply the best practice Security profiles to the traffic, and investigate the alerts or reach out to PANW Support teams
Is it enough to request change ? otherwise, how can we allow this IP ?
Thanks in advance for your reply.
Best regards.
11-27-2024 10:05 AM
Hello,
How are users accessing the site, it looks like via a web browser. I would put the request through via the url filtering portal like you have above. If you need it sooner, you can put in a security policy to allow it and dont apply url filtering to that policy.
Regards,
11-27-2024 12:10 PM
I am a bit confused as to what is being blocked. It is said this is being blocked by the PaloAlto Malicious IP feed, but looking at that EDL I do not currently see the IP listed. Then a test of the IP in the URL Filtering is done and the IP comes up as "Unknown" (which it should because it is a bare IP, not a specific domain/FQDN/URL).
If this is internal users reaching out to a web address that is an IP address instead of a FQDN (ie. https://74.102.229.126 vs. https://example.com ), then as @OtakarKlier said you can create a custom URL Filtering rule to allow that. I don't think PaloAlto would be likely to add an IP to the URL filters.
If this is incoming traffic to your servers from that customer IP and it is being blocked by one of the EDL feeds, then you can open the EDL feed (Objects->External Dynamic Lists->Palo Alto Networks - Known malicious IP addresses->List Entries And Exceptions) and enter an exception address in the "Manual Exceptions" list.
Or perhaps it is being blocked by something that is neither of these cases?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!