- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-09-2022 03:28 AM
Can you please help me clarify the new real-time-detection category, which is covered by the URL filtering license?
According to the article the Advanced URL filtering "real-time-detection" URL category is not a classification by itself, but a real time inspection, which can return either Benign or as one of the risky category types, e.g. Parked, High Risk, etc.
Can you please help me clarify the following:
01-06-2023 12:22 PM
Hi @batd2 and @Schneur_Feldman ,
Like you, I would like to see this recommendation under the URL BP page -> https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/url-filtering/url-filtering-best-practice....
Thanks,
Tom
08-09-2022 07:20 PM
Personally, I have every single category that isn't blocked set to alert. Whatever action you have set, the most restrictive will be the action taken. So if you have real-time-detection set to alert and it's identified as real-time-detection and malware (which you hopefully have set to block) the traffic will be blocked. If you have real-time-detection set to alert and then you get a benign category like social-media that you have set to allow then you would simply alert on the traffic and it would be logged but no action would be taken.
You could alternatively set real-time-detection to allow and the other category identified will always take precedent. If I recall properly this is what the default action for real-time-detection is on the firewall and likely what PAN would recommend since it'll never be the sole detection.
08-10-2022 12:53 AM
@BPry Thank you for your response. Maybe I am missing the point of having the "real-time-detection" category, since the traffic will be classified as Malware, Phishing, etc. My understanding was that the category is used to control if traffic is being sent to Advanced URL filtering servers. Do you think that the queries are sent to the server for inspection, regardless of the the action for real-time-detection?
01-06-2023 11:00 AM
@BPry That does not make a lot of sense. Does anyone have a good explanation as what action for real-time-detection URL category should be set to?
01-06-2023 11:10 AM
Also I tested it. Seems like Real Time needs to be set to Block.
01-06-2023 12:22 PM
Hi @batd2 and @Schneur_Feldman ,
Like you, I would like to see this recommendation under the URL BP page -> https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/url-filtering/url-filtering-best-practice....
Thanks,
Tom
01-07-2023 09:45 AM
I suggest watching the https://register.paloaltonetworks.com/nebula-tech-deep-dive-series sessions that will give you some deep dive.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!