<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Response Page not displayed when using security policy to deny URL category in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/548933#M112041</link>
    <description>&lt;P&gt;I also have same issue. For https website Iam not getting the response page. Any solution?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jul 2023 13:22:40 GMT</pubDate>
    <dc:creator>KhaleelE</dc:creator>
    <dc:date>2023-07-11T13:22:40Z</dc:date>
    <item>
      <title>Response Page not displayed when using security policy to deny URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/380722#M89691</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured a security policy to block a URL category using the &lt;STRONG&gt;Service/URL Category&lt;/STRONG&gt; method and my action is &lt;STRONG&gt;deny&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This works and the category is denied, however the block response page is not displayed. Instead i get "This site can’t be reached" and "&lt;SPAN&gt;ERR_CONNECTION_RESET&lt;/SPAN&gt;".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i block the same category using the URL Filtering Security Profile, the block response page is displayed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This behavior is the same for both encrypted and unencryted pages and also on PAN OS 9.1.7 as well as on 10.0.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea if this is normal behavior or if this is something that i can fix?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Response Page not displayed when using security policy to deny URL category&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 08:00:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/380722#M89691</guid>
      <dc:creator>PerreauLuc</dc:creator>
      <dc:date>2021-01-19T08:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Response Page not displayed when using security policy to deny URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/394719#M91179</link>
      <description>&lt;P&gt;Can you confirm that you are matching the correct policy that just blocks with the the category, also I think before this rule there should be rules that identify the the app id as web-blowsing or ssl, so check the traffic that the app-id is identified correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/test-policy-rule-traffic-matches.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/test-policy-rule-traffic-matches.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you provide a screenshot of the rule as maybe it also has App ID in the rule and maybe you need "Application Block Page" as this triggered first etc.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-response-pages.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-response-pages.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 06:31:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/394719#M91179</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-29T06:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Response Page not displayed when using security policy to deny URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/394840#M91195</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150722"&gt;@PerreauLuc&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Assuming that you are attempting to block an HTTPS site, and that you aren't decrypting said traffic which would cause the issue you are describing, this behavior is expected. You would need to following&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0&lt;/A&gt;&amp;nbsp;to get this functioning. By default, the firewall won't attempt to serve a response page if you aren't decrypting the traffic because it would just lead to a certificate warning.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 23:39:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/394840#M91195</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-03-29T23:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Response Page not displayed when using security policy to deny URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/519002#M107642</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I face the exact same Issue.&lt;/P&gt;
&lt;P&gt;I have enabled response pages and tried it with an url category profile using: &lt;A href="http://urlfiltering.paloaltonetworks.com/test-malware" target="_blank"&gt;http://urlfiltering.paloaltonetworks.com/test-malware&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This worked perfectly fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However: I went on, removed the url profile and added the Service/URL Category "malware", set the rule to deny and I'm presented with a browser message telling me the network connection was interrupted. (no response page)&lt;BR /&gt;So either this is by design / technical limitation or it's a bug.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA-220, 10.2.2&lt;/P&gt;
&lt;P&gt;find my rule below&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MKoehler_0-1666690143359.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44860iF39DD6466302682A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MKoehler_0-1666690143359.png" alt="MKoehler_0-1666690143359.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 09:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/519002#M107642</guid>
      <dc:creator>MKoehler</dc:creator>
      <dc:date>2022-10-25T09:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Response Page not displayed when using security policy to deny URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/520215#M107821</link>
      <description>&lt;P&gt;I am seeing the same behavior. PA-3250 10.2.3&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 19:51:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/520215#M107821</guid>
      <dc:creator>Jake_Aguinaga</dc:creator>
      <dc:date>2022-11-03T19:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Response Page not displayed when using security policy to deny URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/520228#M107824</link>
      <description>&lt;P&gt;To me it would seem to be operating as designed and expected behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With a Security Policy you select targets by some combination of IP, zone, user, service, and/or URL(SNI); and running a deny action you are sending a TCP or UDP reset to the endpoint. It doesn't matter or necessarily operate on HTTP/HTTPS. Therefore the browser just gets a connection closed message, no actual content response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With URL Filtering you are filtering content inside the HTTP/HTTPS connection. So when a block happens you are interrupting the content stream and can return a different content page, vs. just terminating the network connection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 20:56:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/520228#M107824</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-11-03T20:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Response Page not displayed when using security policy to deny URL category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/548933#M112041</link>
      <description>&lt;P&gt;I also have same issue. For https website Iam not getting the response page. Any solution?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 13:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/response-page-not-displayed-when-using-security-policy-to-deny/m-p/548933#M112041</guid>
      <dc:creator>KhaleelE</dc:creator>
      <dc:date>2023-07-11T13:22:40Z</dc:date>
    </item>
  </channel>
</rss>

