<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering log with action allow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528876#M109194</link>
    <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;- The firewall that is generating the URL allow rule, doesn't have any decryption rule at the moment.&lt;/P&gt;
&lt;P&gt;- Matching rule is actually around the bottom, but moving it higher, shouldn't make difference, because the matching source and destination objects are matching only that rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/269747"&gt;@kat3xx&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Indeed the log forwarding is set to forward any log&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_2-1674826965271.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47472i96F3F068362F2D6A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_2-1674826965271.png" alt="Astardzhiev_2-1674826965271.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But this still doesn't explain why rule with no security profile will generate URL log?&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2023 13:45:12 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-01-27T13:45:12Z</dc:date>
    <item>
      <title>URL Filtering log with action allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528157#M109062</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;It seems my whole life is a lie... Apparently PAN FW &lt;U&gt;will generate &lt;/U&gt;URL log for category with action set to allow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yep, and the funnier thing is that you don't even need URL filtering profile applied on the rule. Someone may say I am crazy or I don't understand how PAN FWs work, probably both is true...But how would you explain the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quick background we have IPsec VPN between two PAN fw and we manage both. We have decided to create "trust-all" rule on one end the tunnel and have specific rule only on one of the FWs. For that reason on the far end of the tunnel the rule is "allow any, &lt;U&gt;without any security profile&lt;/U&gt;". Today something got my attention - you guess it - the rule without security profile was generating URL allow logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is how the logs from both firewall looks like&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1674467140717.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47327iB318A105C7260FB2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1674467140717.png" alt="Astardzhiev_0-1674467140717.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And here is the rule without any security profile, that is generating URL log with action allow&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_1-1674467723328.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47328i76A9A6D3F6A09AA5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_1-1674467723328.png" alt="Astardzhiev_1-1674467723328.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems the cause of this phenomena is the Log Forwarding profile.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/view-and-manage-logs/log-types-and-severity-levels/url-filtering-logs" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/view-and-manage-logs/log-types-and-severity-levels/url-filtering-logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_2-1674468007848.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47330iF01A99299211542C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_2-1674468007848.png" alt="Astardzhiev_2-1674468007848.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I was not able to find any other reference to this behavior, but I hope someone prove me wrong and provide any other documentation mentioning this behavior of Log Forwarding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please tell me I am not the only one who was not aware of this, I am flipping tables around here...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am now more curious how this works, if no URL filtering profile is applied why FW is inspecting the SNI. For me this sounds like FW is still performing some kind of inspection (event without any security profile, nor decryption rule also), but will do it silently without generating any log. Until you apply log forwarding for all logs...&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 10:14:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528157#M109062</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-23T10:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering log with action allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528496#M109120</link>
      <description>&lt;P&gt;Is that rule positioned at the very top of your rulebase? if not, can you try putting it there to see if it still logs URLs?&lt;/P&gt;
&lt;P&gt;do you have decryption set up (even no-decrypt) that could be matched?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 08:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528496#M109120</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-01-25T08:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering log with action allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528524#M109124</link>
      <description>&lt;P&gt;Perhaps this is a byproduct of a log forwarding profile with a broad filter?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 12:23:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528524#M109124</guid>
      <dc:creator>kat3xx</dc:creator>
      <dc:date>2023-01-25T12:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering log with action allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528876#M109194</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;- The firewall that is generating the URL allow rule, doesn't have any decryption rule at the moment.&lt;/P&gt;
&lt;P&gt;- Matching rule is actually around the bottom, but moving it higher, shouldn't make difference, because the matching source and destination objects are matching only that rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/269747"&gt;@kat3xx&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Indeed the log forwarding is set to forward any log&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_2-1674826965271.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47472i96F3F068362F2D6A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_2-1674826965271.png" alt="Astardzhiev_2-1674826965271.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But this still doesn't explain why rule with no security profile will generate URL log?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-log-with-action-allow/m-p/528876#M109194</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-27T13:45:12Z</dc:date>
    </item>
  </channel>
</rss>

