Palo Alto Networks has yet to release an App-ID for the new Chinese AI, DeepSeek. Many administrators will probably like to block DeepSeek due its controversiality, and luckily Palo Alto Networks has other ways to achieve this end (Dann haben Wir anderen Metoden).
To identify and allow or block wellknown URLs, Palo Alto offers the “Custom URL Category”.
Create a Custom URL Category and wellknown DeepSeek related URLs. I have identified these so far:
*.deepseek.com/
*.deepseek.com/*
*.deepseek.net/
*.deepseek.net/*
*.deepseekv3.net/
*.deepseekv3.net/*
deepseek.com/
deepseek.com/*
deepseek.net/
deepseek.net/*
deepseekv3.net/
deepseekv3.net/*
Then create a security policy using the new Custom URL Category.
Add all your source zones and as destination zone, your internet zone (here “untrust”). Add the DeepSeek URL Category as URL Category and remember to make the rule drop or block.