Advanced URL Filtering - help me understand it please?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Advanced URL Filtering - help me understand it please?

Hello all,

I have the regular PAN-DB URL filtering and was considering the Advanced URL filtering.

 

From what I understand after reading the documentation, if the PA URL DB recognizes a URL as risky, it sends it to the Advanced URL DB in cloud for real time analysis. Without the advanced URL feature, I'm open to a zero day attack because the URL database on the firewall may not have been updated just yet.

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-ur...

 

"Malicious URLs can be updated or introduced before URL filtering databases have an opportunity to analyze the content; this lag time gives attackers an open period from which they can launch precision attack campaigns on the firewall"

 

I have my Application and Threats updates to download and install every 30 minutes. So I'm figuring this "lag time" is the 30 minutes window, correct?

Also, it says it only forewards URL's that are designated as risky. Wanting to know how many "risky" URL's my current standard URL license detects I want to see if its worth it. But, how do I view "risky" URL's?

 

In your opinion is it worth the purchase, have you found it to be a valuable asset?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @${userLoginName} ,

 


"Malicious URLs can be updated or introduced before URL filtering databases have an opportunity to analyze the content; this lag time gives attackers an open period from which they can launch precision attack campaigns on the firewall"

The lag time is the time between when a malicious URL is introduced and when the URL filtering database [companies] are able to analyze the content and assign categories to it.

 

PAN-DB updates are not done as part of application and threats or any configurable dynamic update.  "PAN-DB does not have daily updates, instead the URL entries are retrieved from the cloud server as needed. The Palo Alto Networks firewall automatically checks for the updates, and system logs are generated every 8 hours indicating if the latest URL-filtering database was downloaded or not." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpMCAS

 

With regard to "risky" URLs, these have not been categorized yet.  They are recommended to be blocked with the "unknown" category.  https://docs.paloaltonetworks.com/best-practices/10-0/internet-gateway-best-practices/best-practice-...  Blocking unknown may occasionally cause valid web sites to be blocked, but exceptions can be made.

 

Finally, The URL Filtering subscription is no longer orderable.  When it is time to renew, the only option will be Advanced URL Filtering.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

2 REPLIES 2

L4 Transporter

Haven't really noticed a difference with this.

Cyber Elite
Cyber Elite

Hi @${userLoginName} ,

 


"Malicious URLs can be updated or introduced before URL filtering databases have an opportunity to analyze the content; this lag time gives attackers an open period from which they can launch precision attack campaigns on the firewall"

The lag time is the time between when a malicious URL is introduced and when the URL filtering database [companies] are able to analyze the content and assign categories to it.

 

PAN-DB updates are not done as part of application and threats or any configurable dynamic update.  "PAN-DB does not have daily updates, instead the URL entries are retrieved from the cloud server as needed. The Palo Alto Networks firewall automatically checks for the updates, and system logs are generated every 8 hours indicating if the latest URL-filtering database was downloaded or not." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpMCAS

 

With regard to "risky" URLs, these have not been categorized yet.  They are recommended to be blocked with the "unknown" category.  https://docs.paloaltonetworks.com/best-practices/10-0/internet-gateway-best-practices/best-practice-...  Blocking unknown may occasionally cause valid web sites to be blocked, but exceptions can be made.

 

Finally, The URL Filtering subscription is no longer orderable.  When it is time to renew, the only option will be Advanced URL Filtering.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 1964 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!