PANOS 7.0.4 and I'm struggling to do something that feels basic 🙂 I need to allow anything on the LAN access to *.sophos.com *.sophosupd.com *.sophosupd.net *.sophosxl.net ocsp2.globalsign.com crl.globalsign.com as per https://community.sophos.com/kb/en-us/121936 Right now we use captive portal but of course machines might try to update when nobody is logged in on them. I can't add "address" objects for entire domains (can I?!) and if I add a URL category and create a rule at the top of my ruleset that allow source "any" to destination "any" with service-http, service-https and application "any", and add the URL category that contans the domains above, I seem to see a lot of matches that I wouldn't expect to, as if other traffic is hitting them. Feels like I've overlooked something daft... thanks!
... View more