We know that in Palo Alto, or in any NGFW, we can allow or block various URL categories. Speaking specifically about the Palo Alto firewall, let's say you have a strict URL filtering policy and decide to block the 'Shareware and Freeware' category.
When you do this, you'll likely have frustrated users complaining that they can't access sites like GitHub, for example.
But, What Did I Do?
So, what did I do now to cause another network issue? Well, Palo Alto categorizes github.com
as 'Shareware and Freeware', so the firewall simply blocks it. There’s a high chance that many other useful sites will get blocked too.
data:image/s3,"s3://crabby-images/0acfd/0acfd1bb9457c242dfadd7e73ebaeb8457588ef6" alt=""
data:image/s3,"s3://crabby-images/5e82c/5e82c0a688eafe3068e8e4b37384c7bd9860d7c7" alt=""
A quick fix is to create a Custom URL Category and add the GitHub URL to it. However, this isn’t a scalable solution.
For instance, if I start with *.github.com
, the firewall may block github.com
. Then, if I add github.com
, the firewall might block URLs like www.github.githubassets.com
. To address this, I’d need to use a different wildcard, but we can’t keep doing this for every affected site.
data:image/s3,"s3://crabby-images/51d85/51d85015ffb90c976098e5e2336d217b92aaa6b3" alt=""
data:image/s3,"s3://crabby-images/2fd18/2fd18ee84d67cb9f7295471713ef357ccd69a03f" alt=""
Combining URL Categories
Instead of managing each URL individually like before, we can create a custom URL category by combining multiple predefined categories.
In this case, I can create a new Custom URL Category and include both 'Shareware and Freeware' and 'Low Risk'. I can then set the action to allow. This means that if a URL matches 'Shareware and Freeware' but is considered low risk, it will be allowed. Everything else will remain blocked.
data:image/s3,"s3://crabby-images/7a89b/7a89b29dfb1ff6d5cc13d7700c39170b96b67b2f" alt=""
Now, users should be able to access GitHub or any other site that falls under the 'Shareware and Freeware' category but is considered low risk.