PAN-DB URL Filtering CLI Command Reference

PAN-DB URL Filtering CLI Command Reference

107233
Created On 09/25/18 19:24 PM - Last Modified 12/07/22 06:19 AM


Environment


  • Palo Alto Firewall.
  • Any PAN-OS.
  • URL Filtering.
  • PAN-DB or Brightcloud URL Database.


Resolution


The below table describes some of the CLI commands associated with URL filtering, including those that are specific to PAN-DB only.

 

Commands

 

  URL Vendor  Comments
CLI CommandDescriptionBrightCloudPAN-DB
"clear"  Commands    
clear url-cache url <url>Clears specified URL from data plane cacheN/ANewPlease note that the URL will not removed from the DP cache however will set to not-resolved and expired.
delete url-database allClears entire MP cacheN/ANew 
delete url-database url <url>Clears specified URL from MP cacheN/ANewPlease note that the URL will not removed from the TRIE however will be expired.
"configure" Commands    
set deviceconfig setting url dynamic-url-timeoutDynamic URL entry timeout in hoursSameN/ADisabled because dynamic URL timeout only applies to BrightCloud
set  deviceconfig system update-schedule url-databaseSchedule for downloading/installing updatesSameN/ADisabled as there are no scheduled updates for Pandora
set  profiles url-filtering profile_name actionaction for block list itemsSameSame 
set profiles url-filtering profile_name  alertcategories to alert onSameSame 
set  profiles url-filtering profile_name allowcategories to allowSameSame 
set  profiles url-filtering profile_name allow-listhost or ip address to passSameSame 
set  profiles url-filtering profile_name blockcategories to blockSameSame 
set  profiles url-filtering profile_name block-listhost or ip address to blockSameSame 
set  profiles url-filtering profile_name continuecategories to block/continueSameSame 
set profiles url-filtering  profile_name descriptiondescriptionSameSame 
set profiles url-filtering profile_name dynamic-urlDynamic URL filteringSameN/ADisabled as this is enabled by default for Pandora.
set profiles url-filtering profile_name enable-container-pageTrack container pageSameSame 
set profiles url-filtering profile_name license-expired allowaction when URL filtering license expiresSameN/ADisabled as this is no longer applicable for PAN-DB.
set profiles url-filtering profile_name license-expired blockaction when URL filtering license expiresSameN/ADisabled as this is no longer applicable for PAN-DB.
set profiles url-filtering profile_name log-container-page-onlyLog container page onlySameSame 
set profiles url-filtering profile_name overridecategories to admin overrideSameSame 
run test  urlTest URL categorizationSameSame 
"delete" Commands    
delete license keyRemove license keys on diskSameSame 
delete dynamic-url host allDelete all dynamic database entriesSameN/ADisabled as this is no longer applicable for PAN-DB.
delete dynamic-url host nameDelete a dynamic database entrySameN/ADisabled as this is no longer applicable for PAN-DB.
delete url-database urlClears a specified URL from management planeN/ANew 
delete url-database brightcloudDeletes the Brightcloud URL DB on the firewallSameN/AThe Brightcloud URL DB is not automatically deleted after migration to PAN-DB. This was done to make it is easy to revert back in case needed. This command was introduced to clear the Brightcloud DB if there is no need to revert
"set" Commands (not configure mode)    
set system setting url-databaseSet URL databaseSameSame 
set system setting url-filtering-feature cacheEnable/disable optional MP URL cache feature for URL filteringSameN/ADisabled as this is no longer applicable for PAN-DB.
set system setting url-filtering-feature filterEnable/disable optional Bloom Filter feature for URL filteringSameN/ADisabled as this is no longer applicable for PAN-DB.
"show"  Commands    
show system infoDisplays current URL Filtering DB version number among other system info.SameSame 
show system stateDisplays system configurationsSameSame 
show running top-urls SameDisabled 
show running url <url>Displays the category of the URL in the dataplane cacheN/ANew 
show running url-cache statisticsDisplays URL cache statisticsSameSame 
show running url-infoShow categorization details of the URL as in the url-cacheN/ANew 
show running url-licenseDisplays URL license informationSameSame 
show system setting url-cache statisticsDisplays URL cache statisticsSameSame 
show system setting url-databaseDisplays URL databaseSameSame 
show system setting url-filtering-featureDisplays URL filtering feature settingsSameDisabled 
show url-cloud statusShows the cloud statusN/ANew 
"request"  Commands    
request url-filtering download paloaltonetworksRequests Pandora URL database seed download.N/AN/AOlder PAN-OS only. Refer note in the additional section
request url-filtering download paloaltonetworks regionRequests regional Pandora URL database seed download.N/AN/AOlder PAN-OS only. Refer note in the additional section
request url-filtering download status vendorShows status of information download for URL filtering based on vendor name.ChangedChangedFor BrightCloud, this command replaces the command:       "request url-filtering download status"
request url-filtering install database major-versionInstalls Major BrightCloud database versionSameN/ADisabled as this is no longer applicable for PAN-DB.
request url-filtering install database md5Installs MD5 of BrightCloud databaseSameN/ADisabled as this is no longer applicable for PAN-DB.
request url-filtering install database minor-versionInstalls Minor BrightCloud database versionSameN/ADisabled as this is no longer applicable for PAN-DB.
request url-filtering install signed-databaseInstall signed uploaded BrightCloud databaseSameN/ADisabled as this is no longer applicable for PAN-DB.
request url-filtering install pandb-databaseInstall PANDB DatabaseN/ANewApplicable to PAN-DB only
request url-filtering revertRevert last url databaseSameN/ADisabled as this is no longer applicable for PAN-DB.
request url-filtering save url-databaseSaves the Pandora database cache in the management planeN/ANew 
request url-filtering update url <url>Updates the specified URL category from the cloudN/ANew 
request url-filtering upgrade BrightcloudUpgrade BrightCloud database(where present)SameN/ADisabled as this is no longer applicable for PAN-DB.
request url-filtering upgrade Brightcloud testCapture initial download in filter-pcap test_bc_download.pcapSameN/ADisabled as this is no longer applicable for PAN-DB.
request license fetch auth-codeAuthentication code for URL vendor licenseSameSame 
request license infoShow information about owned license(s)SameSame 
request license installInstall a license keySameSame 
"test" Commands    
test urlTest URL categorization (MP and Cloud. No DP)SameChangedPAN-DB will provide answers from both device and cloud DB, while BC provides an answer from the cloud DB only if there is no answer in the base DB.
test url-info-cloudReturn detailed information about the URL in the cloudN/ANew 
test url-info-hostReturn detailed information about the URL in the hostN/ANew 

 

 



Additional Information


Note1: In PAN-OS 9.0, the command "request url-filtering download"  only supports BrightCloud URL Filtering

Note2: BrightCloud was removed as a URL filtering vendor starting PAN-OS 9.1. Refer Documentation.  Consequently, the commands "request URL filtering download",  "request URL filtering revert" and "set system setting url-database" are also removed.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXrCAK&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language