- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-21-2022 10:54 AM
Hello all,
I have the regular PAN-DB URL filtering and was considering the Advanced URL filtering.
From what I understand after reading the documentation, if the PA URL DB recognizes a URL as risky, it sends it to the Advanced URL DB in cloud for real time analysis. Without the advanced URL feature, I'm open to a zero day attack because the URL database on the firewall may not have been updated just yet.
"Malicious URLs can be updated or introduced before URL filtering databases have an opportunity to analyze the content; this lag time gives attackers an open period from which they can launch precision attack campaigns on the firewall"
I have my Application and Threats updates to download and install every 30 minutes. So I'm figuring this "lag time" is the 30 minutes window, correct?
Also, it says it only forewards URL's that are designated as risky. Wanting to know how many "risky" URL's my current standard URL license detects I want to see if its worth it. But, how do I view "risky" URL's?
In your opinion is it worth the purchase, have you found it to be a valuable asset?
03-21-2022 06:22 PM
Hi @roma ,
"Malicious URLs can be updated or introduced before URL filtering databases have an opportunity to analyze the content; this lag time gives attackers an open period from which they can launch precision attack campaigns on the firewall"
The lag time is the time between when a malicious URL is introduced and when the URL filtering database [companies] are able to analyze the content and assign categories to it.
PAN-DB updates are not done as part of application and threats or any configurable dynamic update. "PAN-DB does not have daily updates, instead the URL entries are retrieved from the cloud server as needed. The Palo Alto Networks firewall automatically checks for the updates, and system logs are generated every 8 hours indicating if the latest URL-filtering database was downloaded or not." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpMCAS
With regard to "risky" URLs, these have not been categorized yet. They are recommended to be blocked with the "unknown" category. https://docs.paloaltonetworks.com/best-practices/10-0/internet-gateway-best-practices/best-practice-... Blocking unknown may occasionally cause valid web sites to be blocked, but exceptions can be made.
Finally, The URL Filtering subscription is no longer orderable. When it is time to renew, the only option will be Advanced URL Filtering.
Thanks,
Tom
03-21-2022 01:44 PM
Haven't really noticed a difference with this.
03-21-2022 06:22 PM
Hi @roma ,
"Malicious URLs can be updated or introduced before URL filtering databases have an opportunity to analyze the content; this lag time gives attackers an open period from which they can launch precision attack campaigns on the firewall"
The lag time is the time between when a malicious URL is introduced and when the URL filtering database [companies] are able to analyze the content and assign categories to it.
PAN-DB updates are not done as part of application and threats or any configurable dynamic update. "PAN-DB does not have daily updates, instead the URL entries are retrieved from the cloud server as needed. The Palo Alto Networks firewall automatically checks for the updates, and system logs are generated every 8 hours indicating if the latest URL-filtering database was downloaded or not." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpMCAS
With regard to "risky" URLs, these have not been categorized yet. They are recommended to be blocked with the "unknown" category. https://docs.paloaltonetworks.com/best-practices/10-0/internet-gateway-best-practices/best-practice-... Blocking unknown may occasionally cause valid web sites to be blocked, but exceptions can be made.
Finally, The URL Filtering subscription is no longer orderable. When it is time to renew, the only option will be Advanced URL Filtering.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!