Palo Alto is not reading full URL

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Palo Alto is not reading full URL

L2 Linker

We have an in house mail server which have different URLs to access its web mail and administration center. We want to block administration center access from Internet. I tried using URL Filtering but Palo Alto is not reading full URL and only showing host name in URL Filtering logs, I have also imported the the email server ssl certificate on Palo Alto but still same result. Although it is showing full URLs for outgoing web traffic.

 

Please help in this regard.

Best Regards,

Shuaib Khalid
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@Shuaib_Khalid,

I would hazard a guess that you are decrypting outbound traffic and you are not decrypting inbound traffic. If you aren't permorming decryption on the traffic, the firewall is only going to see the base URL. You either need to block this access through your mail server or start decrypting the inbound traffic so the firewall can see the full URL. 

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

If I understand correctly, you are attempting to use URL filtering for inbound traffic. I would say a custom URL category with the full URL and applied to the policy should work.

 

https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/url-filtering

 

Regards,

Cyber Elite
Cyber Elite

@Shuaib_Khalid,

I would hazard a guess that you are decrypting outbound traffic and you are not decrypting inbound traffic. If you aren't permorming decryption on the traffic, the firewall is only going to see the base URL. You either need to block this access through your mail server or start decrypting the inbound traffic so the firewall can see the full URL. 

Hi There,

 

Inbound SSL decryption worked for me, now PA is reading full URL and i have blocked Administration Center URL via URL Filtering. 

 

Thank you so much for help and guidance.

Best Regards,

Shuaib Khalid
  • 1 accepted solution
  • 5990 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!