Custom URL Category and SSL Decryption

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Custom URL Category and SSL Decryption

L0 Member

Hello all,

 

We have a custom URL category created to exclude sites from SSL decyption. We have the category set to no decrypt on the firewall but recently we encountered an issue where URLs that we add to the custom object were not getting categorized as such. We talked to PAN TAC and they recommended adding a "/" to the end of the URLs. We tested this and it seems to be working. Just curious if anyone has seen this before? We have never encountered this before with Custom URL Categories. 

 

Thanks all!

2 REPLIES 2

Cyber Elite
Cyber Elite
It depends on the URLs you're adding to the custom category. The entries are in regex format so some url's may 'register' differently than you'd expect https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/url-filtering/url-filtering-overview/block...
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Have not seen this.  Was working with it yesterday, and as you know without Decryption enabled, you cannot even read the full URL; since, the Client Hello provies only the domain name.  What I learned is to be able to see the URL in the Monitor tab, you need to enable URL filtering on the security policy that matches up with some decryption.

 

At any rate, we have been using a lot of * asterisks.  For example:  example.com/noaccess/*

Have you tried that?

  • 3911 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!