cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

Cyber Elite
Cyber Elite

Hi @YGoldy ,

 

You mentioned that you also wanted to exclude intrusion detection.  This may include Vulnerability, Antivirus, and other profiles and cannot be done entirely with a URL Filtering profile.

 

You could put a custom URL category as a destination in a security policy rule.  I didn't think that IP addresses could be put in a custom URL category, but this doc says you can.  https://docs.paloaltonetworks.com/advanced-url-filtering/administration/configuring-url-filtering/ur...

 

A custom URL category would make the security policy rule cleaner without the long list of URLs or IP addresses.

 

If this list will change frequently, you can use an EDL that you edit on a web server off the NGFW and do not have to commit with each change.  The NGFW can be configured to check the EDL every 5 minutes.  The doc above says a URL List type EDL can contain IP addresses and domains.  I did not know that either.

 

https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-po...

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

Who rated this post