The specific URL is not shown in the traffic log

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

The specific URL is not shown in the traffic log

L3 Networker

PAN OS 9.1.7

The following traffic log shows the  specific URL

3.png

The other traffic log doesn't have the specific URL, and also this log cannot be seen in the url filtering log 

4.png

Is this a expected behaviors or something wrong with the customer's environment?

 

 

3 REPLIES 3

Cyber Elite
Cyber Elite

@zji,

First and foremost, PAN-OS 9.1.7 is severely dated. I'd advising your customer to upgrade to 9.1.15-h1.

 

Lastly the detail that you're giving doesn't really specify how the "Deny All 2020-URL" is actually configured. If the traffic was denied due to URL you'd expect to see the URL recorded in the logs as it is in your first example. If the traffic was denied before the URL was analyzed however, the firewall won't record the URL that the client requested. So from what's been provided and the action being reset-both with no further information provided, it appears as though this is expected behavior and the URL shouldn't be recorded. 

The  "Deny All 2020-URL" only define the custom url category, so if the packets hit this rule that mean they actually denied by the URL, right?

5.png 

@BPry 

Thanks for your reply! 

Since the security rule only define custom url category and I can see "url category" in the traffic log, does this mean it actually check URL? So I'm confused that why the packet didn't record the specific URL.

  • 1653 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!