<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recommended action for real-time-detection URL category in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526241#M108775</link>
    <description>&lt;P&gt;I suggest watching the &lt;A href="https://register.paloaltonetworks.com/nebula-tech-deep-dive-series" target="_blank"&gt;https://register.paloaltonetworks.com/nebula-tech-deep-dive-series&lt;/A&gt; sessions that will give you some deep dive.&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jan 2023 17:45:53 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2023-01-07T17:45:53Z</dc:date>
    <item>
      <title>Recommended action for real-time-detection URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/511295#M106301</link>
      <description>&lt;P&gt;Can you please help me clarify the new real-time-detection category, which is covered by the URL filtering license?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to the article the Advanced URL filtering&amp;nbsp; "real-time-detection" URL category is not a classification by itself, but a real time inspection, which can return either Benign or as one of the risky category types, e.g. Parked, High Risk, etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001VzpCAE" target="_blank"&gt;The logging entry with real-time-detection category is rarely s... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please help me clarify the&amp;nbsp; following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;What is the recommended action&amp;nbsp; real-time-detection in a URL filtering profile?&lt;/LI&gt;
&lt;LI&gt;Will action "alert" permit any traffic detected by the Advanced URL filtering, regardless of the risk and will setting it to block, also block benign traffic?&lt;/LI&gt;
&lt;LI&gt;Do action "allow" disables real time Advanced URL inspection checks?&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 09 Aug 2022 10:28:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/511295#M106301</guid>
      <dc:creator>batd2</dc:creator>
      <dc:date>2022-08-09T10:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended action for real-time-detection URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/511388#M106313</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130874"&gt;@batd2&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Personally, I have every single category that isn't blocked set to alert. Whatever action you have set, the most restrictive will be the action taken. So if you have real-time-detection set to alert and it's identified as real-time-detection and malware (which you hopefully have set to block) the traffic will be blocked. If you have real-time-detection set to alert and then you get a benign category like social-media that you have set to allow then you would simply alert on the traffic and it would be logged but no action would be taken.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could alternatively set real-time-detection to allow and the other category identified will always take precedent. If I recall properly this is what the default action for real-time-detection is on the firewall and likely what PAN would recommend since it'll never be the sole detection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 02:20:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/511388#M106313</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-08-10T02:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended action for real-time-detection URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/511407#M106319</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thank you for your response. Maybe I am missing the point of having the "real-time-detection" category, since the traffic will be classified as Malware, Phishing, etc. My understanding was that the category is used to control if traffic is being sent to Advanced URL filtering servers. Do you think that the queries are sent to the server for inspection, regardless of the the action for real-time-detection?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 07:53:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/511407#M106319</guid>
      <dc:creator>batd2</dc:creator>
      <dc:date>2022-08-10T07:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended action for real-time-detection URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526195#M108766</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; That does not make a lot of sense. Does anyone have a good explanation as what&amp;nbsp;&lt;SPAN&gt;action for real-time-detection URL category should be set to?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 19:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526195#M108766</guid>
      <dc:creator>Schneur_Feldman</dc:creator>
      <dc:date>2023-01-06T19:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended action for real-time-detection URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526196#M108767</link>
      <description>&lt;P&gt;Also I tested it. Seems like Real Time needs to be set to Block.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 19:10:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526196#M108767</guid>
      <dc:creator>Schneur_Feldman</dc:creator>
      <dc:date>2023-01-06T19:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended action for real-time-detection URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526200#M108768</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130874"&gt;@batd2&lt;/a&gt; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204018"&gt;@Schneur_Feldman&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;This document says that the real-time-detection category should be set to alert -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/url-filtering/test-url-filtering-configuration" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/url-filtering/test-url-filtering-configuration&lt;/A&gt; (note under Verify Advanced URL Filtering).&amp;nbsp; A-URL will then reclassify the URL and the action will be taken according to the new category.&amp;nbsp; They have URLs to test and see the logs for yourself.&lt;/LI&gt;
&lt;LI&gt;"Alert" will not permit all traffic that matches the category.&amp;nbsp; As explained in the doc, the most severe action will be taken from all the matched categories.&amp;nbsp; "Block" will block all traffic that matches the category because it is the most severe action.&lt;/LI&gt;
&lt;LI&gt;"Allow" does not log.&amp;nbsp; So, it makes sense that it disables real-time checks that match this category.&amp;nbsp; Inline Deep Learning (10.2) &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-new-features/url-filtering-features/cloud-inline-categorization" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-new-features/url-filtering-features/cloud-inline-categorization&lt;/A&gt; is also part of A-URL.&amp;nbsp; So, I don't think it completely disables A-URL.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Like you, I would like to see this recommendation under the URL BP page -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/url-filtering/url-filtering-best-practices" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/url-filtering/url-filtering-best-practices&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 20:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526200#M108768</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-06T20:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended action for real-time-detection URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526241#M108775</link>
      <description>&lt;P&gt;I suggest watching the &lt;A href="https://register.paloaltonetworks.com/nebula-tech-deep-dive-series" target="_blank"&gt;https://register.paloaltonetworks.com/nebula-tech-deep-dive-series&lt;/A&gt; sessions that will give you some deep dive.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 17:45:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-action-for-real-time-detection-url-category/m-p/526241#M108775</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-01-07T17:45:53Z</dc:date>
    </item>
  </channel>
</rss>

