<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need clarification on URL Filtering logs in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583898#M2997</link>
    <description>&lt;P&gt;correct&lt;/P&gt;
&lt;P&gt;the log is generated from the url decoder action, which is only triggered if you let the 'base' traffic (tcp connection) pass which is achieved by setting the security rule to allow&lt;/P&gt;
&lt;P&gt;Advantage of this approach is also that users will receive a nice block page in their browser versus a failed connection with no context&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2024 13:54:28 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2024-04-16T13:54:28Z</dc:date>
    <item>
      <title>Need clarification on URL Filtering logs</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583829#M2990</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;Please help me get through this.&lt;/P&gt;
&lt;P&gt;We have configured PA-450 firewall and everything is working fine as expected.&lt;BR /&gt;But, We have used the option URL category in the security policy without an URL filtering profile for all user group. Which is working fine but I cant see any URL user activity report.&lt;BR /&gt;But we need block URL summary report.&lt;/P&gt;
&lt;P&gt;Then I found out that we need block or alert action in order to get URL logs.&lt;/P&gt;
&lt;P&gt;Current Scenario&lt;BR /&gt;=================&lt;BR /&gt;(Its not the real configuration setup from the firewall, just a prototype)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Arun_R_0-1713249886072.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59090iFDCFB0B2CC2279CB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Arun_R_0-1713249886072.png" alt="Arun_R_0-1713249886072.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The above screenshot is the current scenario of the security policies which has URL category directly mapped in polices.&lt;BR /&gt;There are no Block URL user activity report generated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please observe the below workaround.&lt;/P&gt;
&lt;P&gt;Workaround&lt;BR /&gt;============&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Arun_R_1-1713250275858.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59091i578F2F343F833E31/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Arun_R_1-1713250275858.png" alt="Arun_R_1-1713250275858.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Please observe the above screenshot.&lt;BR /&gt;Above we have all the URL category mapped allow policies which generates no logs.&lt;BR /&gt;What if I create a security policy with a URL profile which blocks all the category at the bottom.&lt;/P&gt;
&lt;P&gt;All the allowed traffic will hit on the above rules for all user groups and other traffics will hit on the bottom block rule and generates the Block URL user activity summary ... right ?&lt;/P&gt;
&lt;P&gt;Please correct me if I am wrong.&lt;/P&gt;
&lt;P&gt;NOTE: We don't want to use URL Filtering Profile. Instead we need the carry on with current scenario.&lt;/P&gt;
&lt;P&gt;Please help me with this doubt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 06:51:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583829#M2990</guid>
      <dc:creator>Arun_R</dc:creator>
      <dc:date>2024-04-16T06:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Need clarification on URL Filtering logs</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583841#M2993</link>
      <description>&lt;P&gt;you'll need to set that 'block all' rule to &lt;STRONG&gt;allow&lt;/STRONG&gt; since a deny rule will not put packets into l7 for inspection, so you wont hit the url filtering block action, and get no logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dare i ask why you're not using url filtering to allow url categories? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 07:38:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583841#M2993</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-04-16T07:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need clarification on URL Filtering logs</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583864#M2994</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your reply,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if we configure the last Block Rule and set all the predefined URL category to "Block" and rule as "Allow"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We will get the URL user activity summary right ?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 08:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583864#M2994</guid>
      <dc:creator>Arun_R</dc:creator>
      <dc:date>2024-04-16T08:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Need clarification on URL Filtering logs</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583898#M2997</link>
      <description>&lt;P&gt;correct&lt;/P&gt;
&lt;P&gt;the log is generated from the url decoder action, which is only triggered if you let the 'base' traffic (tcp connection) pass which is achieved by setting the security rule to allow&lt;/P&gt;
&lt;P&gt;Advantage of this approach is also that users will receive a nice block page in their browser versus a failed connection with no context&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 13:54:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/need-clarification-on-url-filtering-logs/m-p/583898#M2997</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-04-16T13:54:28Z</dc:date>
    </item>
  </channel>
</rss>

