Palo Alto is not reading full URL

Reply
Highlighted
L2 Linker

Palo Alto is not reading full URL

We have an in house mail server which have different URLs to access its web mail and administration center. We want to block administration center access from Internet. I tried using URL Filtering but Palo Alto is not reading full URL and only showing host name in URL Filtering logs, I have also imported the the email server ssl certificate on Palo Alto but still same result. Although it is showing full URLs for outgoing web traffic.

 

Please help in this regard.

Best Regards,

Shuaib Khalid
Tags (1)

Accepted Solutions
Highlighted
Cyber Elite

@Shuaib_Khalid,

I would hazard a guess that you are decrypting outbound traffic and you are not decrypting inbound traffic. If you aren't permorming decryption on the traffic, the firewall is only going to see the base URL. You either need to block this access through your mail server or start decrypting the inbound traffic so the firewall can see the full URL. 

View solution in original post


All Replies
Highlighted
Cyber Elite

Hello,

If I understand correctly, you are attempting to use URL filtering for inbound traffic. I would say a custom URL category with the full URL and applied to the policy should work.

 

https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/url-filtering

 

Regards,

Highlighted
Cyber Elite

@Shuaib_Khalid,

I would hazard a guess that you are decrypting outbound traffic and you are not decrypting inbound traffic. If you aren't permorming decryption on the traffic, the firewall is only going to see the base URL. You either need to block this access through your mail server or start decrypting the inbound traffic so the firewall can see the full URL. 

View solution in original post

Highlighted
L2 Linker

Hi There,

 

Inbound SSL decryption worked for me, now PA is reading full URL and i have blocked Administration Center URL via URL Filtering. 

 

Thank you so much for help and guidance.

Best Regards,

Shuaib Khalid
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!