Recommended action for real-time-detection URL category

cancel
Showing results for 
Search instead for 
Did you mean: 

Recommended action for real-time-detection URL category

L4 Transporter

Can you please help me clarify the new real-time-detection category, which is covered by the URL filtering license? 

 

According to the article the Advanced URL filtering  "real-time-detection" URL category is not a classification by itself, but a real time inspection, which can return either Benign or as one of the risky category types, e.g. Parked, High Risk, etc. 

The logging entry with real-time-detection category is rarely s... - Knowledge Base - Palo Alto Netw...

 

Can you please help me clarify the  following:

  1. What is the recommended action  real-time-detection in a URL filtering profile?
  2. Will action "alert" permit any traffic detected by the Advanced URL filtering, regardless of the risk and will setting it to block, also block benign traffic?
  3. Do action "allow" disables real time Advanced URL inspection checks? 
2 REPLIES 2

Cyber Elite
Cyber Elite

@batd2,

Personally, I have every single category that isn't blocked set to alert. Whatever action you have set, the most restrictive will be the action taken. So if you have real-time-detection set to alert and it's identified as real-time-detection and malware (which you hopefully have set to block) the traffic will be blocked. If you have real-time-detection set to alert and then you get a benign category like social-media that you have set to allow then you would simply alert on the traffic and it would be logged but no action would be taken.

 

You could alternatively set real-time-detection to allow and the other category identified will always take precedent. If I recall properly this is what the default action for real-time-detection is on the firewall and likely what PAN would recommend since it'll never be the sole detection. 

L4 Transporter

@BPry Thank you for your response. Maybe I am missing the point of having the "real-time-detection" category, since the traffic will be classified as Malware, Phishing, etc. My understanding was that the category is used to control if traffic is being sent to Advanced URL filtering servers. Do you think that the queries are sent to the server for inspection, regardless of the the action for real-time-detection? 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!