<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with URL Filtering Order in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/402339#M91788</link>
    <description>&lt;P&gt;Just wanted to post on this subject since I appears that PAN has updated the behavior of precedence in URL Filtering Profiles.&lt;/P&gt;&lt;P&gt;On systems running 8.X code, it does appear that the order of precendence follows what is outlined in&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC," target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC,&lt;/A&gt;&amp;nbsp;however, I am running 9.0.6 on my PA-220, and URL Filtering appears to have an additional factor in assigning priority...the source of the list (custom, EDL, pre-defined).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran a test of this in my lab.&amp;nbsp; In this example, I'm browsing to "jack.com".&amp;nbsp; You can see the URL is ultimately categorized as "streaming-media", however there is a list that shows all lists that this URL is a member of...interesting to note, it shows my EDL "URL", but I have this set to "none" in the filter profile, so I would have expected it to not show up, just the same as my custom URL categories, but it's there.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.log1.JPG" style="width: 834px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32580i3742E3033891E427/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.log1.JPG" alt="1.log1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a custom URL category and EDL that both have entry "jack.com"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.cust-cat.JPG" style="width: 551px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32582i5BF3C79B4C0B3F2B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.cust-cat.JPG" alt="3.cust-cat.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.edl.JPG" style="width: 313px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32583i2ABF4FF3991F2EBF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4.edl.JPG" alt="4.edl.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my URL filtering profile, I have my custom URL category set to "none".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.url-filter-cust.JPG" style="width: 696px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32584iD945593135911186/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="5.url-filter-cust.JPG" alt="5.url-filter-cust.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have my EDL set to "none".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.url-filter-edl.JPG" style="width: 726px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32585i8A4107B560130DCA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="6.url-filter-edl.JPG" alt="6.url-filter-edl.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Per the logs, I know the pre-defined categories of "streaming-media" and "low-risk" were listed, so those are set to "alert".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.url-filter-stream.JPG" style="width: 717px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32586i4E758393AC4C3CAD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="7.url-filter-stream.JPG" alt="7.url-filter-stream.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.url-filter-low.JPG" style="width: 703px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32587iE2625B4F5A63A15C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="8.url-filter-low.JPG" alt="8.url-filter-low.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, to test the effect of "block" versus "alert" in the same category group, I change "low-risk" to block to see if it will take precedence over "streaming-media".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.url-filter-low-block.JPG" style="width: 730px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32588iE616984A01CE2228/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="9.url-filter-low-block.JPG" alt="9.url-filter-low-block.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It does, as the category is now "low-risk" and the action is "block-url".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.log2.JPG" style="width: 920px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32589i6D45A8EDB98F351B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="10.log2.JPG" alt="10.log2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, with "low-risk" still set to block, I update my EDL entry to "alert" and test traffic again.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.url-filter-edl-alert.JPG" style="width: 699px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32590iF25426FF24FAB62C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="11.url-filter-edl-alert.JPG" alt="11.url-filter-edl-alert.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sure enough, the EDL alert took priority over the pre-defined category block.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.log3.JPG" style="width: 910px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32591i5F93EAE3B041B9C3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="12.log3.JPG" alt="12.log3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course, if I set the EDL to "block", it's still the matching category and does block as expected.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.url-filter-edl-block.JPG" style="width: 699px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32592iEA163EE84316DAAC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="13.url-filter-edl-block.JPG" alt="13.url-filter-edl-block.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="14.log4.JPG" style="width: 915px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32593i9F6C8DAC36E951E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="14.log4.JPG" alt="14.log4.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, with the pre-defined and EDL categories blocking, I update my custom URL category to "alert".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="15.url-filter-cust-alert.JPG" style="width: 711px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32594iF206B917D8E69073/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="15.url-filter-cust-alert.JPG" alt="15.url-filter-cust-alert.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The traffic is reclassified as the custom category, and the traffic is allowed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="16.log5.JPG" style="width: 915px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32595iA2FE69BFB333A15C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="16.log5.JPG" alt="16.log5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end, my URL filter profile looks like this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="17.final-filter.JPG" style="width: 628px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32596iC8F184BC158C96C2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="17.final-filter.JPG" alt="17.final-filter.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on this behavior, it does appear that Palo provides a legend of matching priority based on how the groups are listed in the filtering profile (top down: custom, EDL, pre-defined).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.url-filter.JPG" style="width: 775px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32597iD5DE936BC37FEA91/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.url-filter.JPG" alt="2.url-filter.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just wanted to point this out since it does appear that with 8.X code, regardless of the category group, a URL matching any "block" category cannot be overriden, regardless of the category group, but with 9.X, it is now possible.&amp;nbsp; Personally, I like this feature.&amp;nbsp; If PAN categorizes a web site to a specific category that I happen to be blocking in a URL filtering profile, I can use a custom category "white list" to allow it, avoiding any need to make a new policy with matching criteria and a different content inspection profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Apr 2021 17:00:18 GMT</pubDate>
    <dc:creator>jbworley</dc:creator>
    <dc:date>2021-04-27T17:00:18Z</dc:date>
    <item>
      <title>Problem with URL Filtering Order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/251636#M71553</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need a help in my case, i have a bunch of urls which must be permitted and any thing else must be denied. so i create a white list url using the (Custom Objects - URL Filtering) and then i create a URL Security Profile and blocked every categories and just alert my URL Filtering white list and then add it to my (Inside to Outside) policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is here when i monitor the url filtering i found some of my urls are blocked beacuse it is exist in another categories like (Computer-and-Internet-info),&amp;nbsp; i think because of URL filtering order which describe that the order first for the blocked list then the allow list then the custom categories.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any one face this problem before and if there any tricks to jumb over the order and mke this happen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to add my custom object directly to my policy and not to use the profile but in this case i can't know the url which will be blocked and in some times i need this to monitor my urls and to know if i need to open some more urls related to our network activity.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 07:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/251636#M71553</guid>
      <dc:creator>DerarAbubaker</dc:creator>
      <dc:date>2019-02-28T07:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with URL Filtering Order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/251652#M71554</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107948"&gt;@DerarAbubaker&lt;/a&gt;&amp;nbsp;, do you have the same URLs configured in different custom URL catogaries, if so, please not that block have more preference than alert.&lt;/P&gt;&lt;P&gt;Please check if below document helps,&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note that whatever url catogary you directly add to policy is a matching condition, it may not address your requirment&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 08:07:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/251652#M71554</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-02-28T08:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with URL Filtering Order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/251654#M71556</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;i have just one custom URL category but the conflicts happen between my custom category which have my white listed URLs and with the predifiened categories like ( Computer-and-Internet-info ) , i need to block all the predifiened categories and just permit my custom URLs to allow.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 08:11:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/251654#M71556</guid>
      <dc:creator>DerarAbubaker</dc:creator>
      <dc:date>2019-02-28T08:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with URL Filtering Order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/251660#M71559</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107948"&gt;@DerarAbubaker&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you trying to allow any subdomains?. (eg. &lt;A href="http://www.xyz.com/abc" target="_blank"&gt;www.xyz.com/abc&lt;/A&gt;) ?)&lt;/P&gt;&lt;P&gt;For this granularity, you need to have decryption.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 08:36:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/251660#M71559</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-02-28T08:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with URL Filtering Order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/252034#M71659</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&amp;nbsp;thanks for your help, actually no because i have many subdomains for this domain and it will be many others in future so it is not a solution could i use even if its working. What about the decryption what do you mean of this? What should i do? and How could decryption help to solve this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another question how Paloalto firewall decide that this spacific non-public URL belong to that category?&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2019 14:39:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/252034#M71659</guid>
      <dc:creator>DerarAbubaker</dc:creator>
      <dc:date>2019-03-02T14:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with URL Filtering Order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/402339#M91788</link>
      <description>&lt;P&gt;Just wanted to post on this subject since I appears that PAN has updated the behavior of precedence in URL Filtering Profiles.&lt;/P&gt;&lt;P&gt;On systems running 8.X code, it does appear that the order of precendence follows what is outlined in&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC," target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsmCAC,&lt;/A&gt;&amp;nbsp;however, I am running 9.0.6 on my PA-220, and URL Filtering appears to have an additional factor in assigning priority...the source of the list (custom, EDL, pre-defined).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran a test of this in my lab.&amp;nbsp; In this example, I'm browsing to "jack.com".&amp;nbsp; You can see the URL is ultimately categorized as "streaming-media", however there is a list that shows all lists that this URL is a member of...interesting to note, it shows my EDL "URL", but I have this set to "none" in the filter profile, so I would have expected it to not show up, just the same as my custom URL categories, but it's there.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.log1.JPG" style="width: 834px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32580i3742E3033891E427/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.log1.JPG" alt="1.log1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a custom URL category and EDL that both have entry "jack.com"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.cust-cat.JPG" style="width: 551px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32582i5BF3C79B4C0B3F2B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.cust-cat.JPG" alt="3.cust-cat.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.edl.JPG" style="width: 313px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32583i2ABF4FF3991F2EBF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4.edl.JPG" alt="4.edl.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my URL filtering profile, I have my custom URL category set to "none".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.url-filter-cust.JPG" style="width: 696px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32584iD945593135911186/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="5.url-filter-cust.JPG" alt="5.url-filter-cust.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have my EDL set to "none".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.url-filter-edl.JPG" style="width: 726px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32585i8A4107B560130DCA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="6.url-filter-edl.JPG" alt="6.url-filter-edl.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Per the logs, I know the pre-defined categories of "streaming-media" and "low-risk" were listed, so those are set to "alert".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.url-filter-stream.JPG" style="width: 717px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32586i4E758393AC4C3CAD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="7.url-filter-stream.JPG" alt="7.url-filter-stream.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.url-filter-low.JPG" style="width: 703px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32587iE2625B4F5A63A15C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="8.url-filter-low.JPG" alt="8.url-filter-low.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, to test the effect of "block" versus "alert" in the same category group, I change "low-risk" to block to see if it will take precedence over "streaming-media".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.url-filter-low-block.JPG" style="width: 730px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32588iE616984A01CE2228/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="9.url-filter-low-block.JPG" alt="9.url-filter-low-block.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It does, as the category is now "low-risk" and the action is "block-url".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.log2.JPG" style="width: 920px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32589i6D45A8EDB98F351B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="10.log2.JPG" alt="10.log2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, with "low-risk" still set to block, I update my EDL entry to "alert" and test traffic again.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.url-filter-edl-alert.JPG" style="width: 699px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32590iF25426FF24FAB62C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="11.url-filter-edl-alert.JPG" alt="11.url-filter-edl-alert.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sure enough, the EDL alert took priority over the pre-defined category block.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.log3.JPG" style="width: 910px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32591i5F93EAE3B041B9C3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="12.log3.JPG" alt="12.log3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course, if I set the EDL to "block", it's still the matching category and does block as expected.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.url-filter-edl-block.JPG" style="width: 699px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32592iEA163EE84316DAAC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="13.url-filter-edl-block.JPG" alt="13.url-filter-edl-block.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="14.log4.JPG" style="width: 915px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32593i9F6C8DAC36E951E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="14.log4.JPG" alt="14.log4.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, with the pre-defined and EDL categories blocking, I update my custom URL category to "alert".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="15.url-filter-cust-alert.JPG" style="width: 711px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32594iF206B917D8E69073/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="15.url-filter-cust-alert.JPG" alt="15.url-filter-cust-alert.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The traffic is reclassified as the custom category, and the traffic is allowed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="16.log5.JPG" style="width: 915px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32595iA2FE69BFB333A15C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="16.log5.JPG" alt="16.log5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end, my URL filter profile looks like this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="17.final-filter.JPG" style="width: 628px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32596iC8F184BC158C96C2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="17.final-filter.JPG" alt="17.final-filter.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on this behavior, it does appear that Palo provides a legend of matching priority based on how the groups are listed in the filtering profile (top down: custom, EDL, pre-defined).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.url-filter.JPG" style="width: 775px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32597iD5DE936BC37FEA91/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.url-filter.JPG" alt="2.url-filter.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just wanted to point this out since it does appear that with 8.X code, regardless of the category group, a URL matching any "block" category cannot be overriden, regardless of the category group, but with 9.X, it is now possible.&amp;nbsp; Personally, I like this feature.&amp;nbsp; If PAN categorizes a web site to a specific category that I happen to be blocking in a URL filtering profile, I can use a custom category "white list" to allow it, avoiding any need to make a new policy with matching criteria and a different content inspection profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 17:00:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-url-filtering-order/m-p/402339#M91788</guid>
      <dc:creator>jbworley</dc:creator>
      <dc:date>2021-04-27T17:00:18Z</dc:date>
    </item>
  </channel>
</rss>

