I've a private subnet in AWS that needs to be locked out from Internet access. But the instances in this private subnet need to access specific set of hosts (say update.java.com, update.ubuntu.com etc). Obviously the IP address associated with these hosts are dynamic. Does Palo Alto Networks Firewall (or any other solution) solve this scenario? If so, please provide pointers.
You can create custom URL and allow internet traffic for those URL for a specific subnet.
Please refer the following doc.
-- Hardik Shah
PAYG2 will have support for URL Filtering
If all you need to do is create a customer URL category and define the URLs then you shouldn't need a URL filtering license for that. But if you want URL filtering then PAYG2 is the way to go there.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!