- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-07-2018 01:38 PM
I want to look at the url address of a data packet that was blocked by a deny rule. I had url filtering applied on the rule but the denied traffic log shows the url category but not the url address. Please advise me in logging url address for denied traffic.
TIA
09-07-2018 01:57 PM
In all likelyhood you are blocking this traffic before the firewall would ever look at the URL, and therefore there is no reason to record this information.
Say for instance I've blocked access to 54.225.121.9. The URL of that IP is never recorded because the firewall never looks at it, because it knows that it needs to block the traffic before it ever needs to look at the URl.
09-07-2018 05:25 PM
@BPryhow come it showes the url category?
09-07-2018 11:40 PM - edited 09-10-2018 10:35 AM
How does your securitd policy rule look like or more precisely: how did you configure URL filtering? Did you add an URL filtering security profile or you just added the categories directly to the rule?
09-10-2018 10:20 AM
I had the complete url filering applied under profiles in action tab.
09-10-2018 10:46 AM
Did you check the "URL Log" or opened the detail of such a denied session in the traffic log?
02-20-2023 06:39 PM
Sorry to bother you, may I ask did you figure out why the denied traffic log shows the url category but not the url address? Since my customer faced the same issue, there are only custom url category defined in the security rule and the action is deny.
05-22-2023 02:26 PM
Were you ever able to figure this out? I have the same question
08-27-2023 11:48 AM
I think it depends on how the traffic is blocked. If you have an IP based drop rule, the firewall is not able to log the actual URL. With a drop rule with an URL added direcrly to the rule a log is written, at least in new PAN-OS versions, so maybe this was a bug in the past, that then no url log was written - or a new feature that was implemented.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!