<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Profile/ URL Filter enable but web site bypass blocking in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576371#M2133</link>
    <description>&lt;P&gt;I updated to release 11.1.0 and it doesn't work nevertheless.&lt;/P&gt;
&lt;P&gt;Last way is Dynamic Updates&lt;/P&gt;</description>
    <pubDate>Wed, 07 Feb 2024 07:56:17 GMT</pubDate>
    <dc:creator>marco.giraldo</dc:creator>
    <dc:date>2024-02-07T07:56:17Z</dc:date>
    <item>
      <title>Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576252#M2121</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Platform: PA-440&lt;/P&gt;
&lt;P&gt;SW Version: 10.1.8&lt;/P&gt;
&lt;P&gt;I created policy and I enabled Actions/Profile settings/URL Filter with customized one, it locks adult content.&lt;/P&gt;
&lt;P&gt;1st attempt&lt;/P&gt;
&lt;P&gt;website like chaturbate.com doesn't lock, in Monitor/URL filter appear blocked but I can browse the web site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2nd attempt&lt;/P&gt;
&lt;P&gt;I create an URL filter category with specific web site and it happens the same thing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why does it work so strange?&lt;/P&gt;
&lt;P&gt;#PA440&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 13:36:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576252#M2121</guid>
      <dc:creator>marco.giraldo</dc:creator>
      <dc:date>2024-02-06T13:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576260#M2122</link>
      <description>&lt;P&gt;Out of curiosity, do you alert on all other url categories? What does your custom url category look like? Do you use a wildcard at some point or just the specific url?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first thing that comes to mind with the actual url category is its not hearing back quick enough on the first time its seeing this. What happens if you lower the category lookup timeout?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Claw4609_0-1707228393878.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57397i367EF30157D7B3B4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Claw4609_0-1707228393878.png" alt="Claw4609_0-1707228393878.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 14:06:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576260#M2122</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-02-06T14:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576265#M2123</link>
      <description>&lt;P&gt;Out of curiosity, do you alert on all other url categories?&amp;nbsp;&lt;STRONG&gt;No, logs appear when web site is blocked.&lt;/STRONG&gt; What does your custom url category look like? &lt;STRONG&gt;Lock adult category and I added specific URL&lt;/STRONG&gt; Do you use a wildcard at some point or just the specific url? &lt;STRONG&gt;Specific URL.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But as you can see the log, web site is blocked but I can browse it nevertheless.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Category lookup timeout (sec) =2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;And hold client request for category lookup is checked&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 14:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576265#M2123</guid>
      <dc:creator>marco.giraldo</dc:creator>
      <dc:date>2024-02-06T14:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576267#M2124</link>
      <description>&lt;P&gt;If you also add *.url.com/ to the custom list does it then block as intended? The custom url category may not be blocking all that it needs to. Granted that wouldn't explain why the predefined category isnt blocking it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you go into the cli of the firewall and run "test url&amp;nbsp;&lt;EM&gt;URL&lt;/EM&gt;" does the output categorize correctly? Could try clearing the url cache as well:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPeYCAW" target="_blank"&gt;How to clear URL cache in management and data plane? - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 14:49:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576267#M2124</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-02-06T14:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576283#M2125</link>
      <description>&lt;P&gt;If I try via cli to check the url it appears as adult category but it works again.&lt;/P&gt;
&lt;P&gt;In my custom category I tried to add other web site: *.acmilan.com and it locks both http and https.&lt;/P&gt;
&lt;P&gt;In https blocked web site doesn't appear custom web page, but it is other topic.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 15:28:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576283#M2125</guid>
      <dc:creator>marco.giraldo</dc:creator>
      <dc:date>2024-02-06T15:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576284#M2126</link>
      <description>&lt;P&gt;Without decrypting the traffic the custom web pages are a lot less reliable. But here is a document you could follow:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0" target="_blank"&gt;How to Serve a URL Response Page Over an HTTPS Session Without ... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 15:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576284#M2126</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-02-06T15:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576285#M2127</link>
      <description>&lt;P&gt;This evening we will try to update version.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 15:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576285#M2127</guid>
      <dc:creator>marco.giraldo</dc:creator>
      <dc:date>2024-02-06T15:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576371#M2133</link>
      <description>&lt;P&gt;I updated to release 11.1.0 and it doesn't work nevertheless.&lt;/P&gt;
&lt;P&gt;Last way is Dynamic Updates&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 07:56:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576371#M2133</guid>
      <dc:creator>marco.giraldo</dc:creator>
      <dc:date>2024-02-07T07:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile/ URL Filter enable but web site bypass blocking</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576645#M2141</link>
      <description>&lt;P&gt;Do you see it in the traffic as tcp 443?&lt;/P&gt;
&lt;P&gt;It could be udp QUIC traffic. Block QUIC and see if that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 16:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/security-profile-url-filter-enable-but-web-site-bypass-blocking/m-p/576645#M2141</guid>
      <dc:creator>Rick-Rowe</dc:creator>
      <dc:date>2024-02-08T16:52:29Z</dc:date>
    </item>
  </channel>
</rss>

