url-filtering

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

url-filtering

L4 Transporter


Hi,

In url filtering adult-and-pornography blocked . But la-xxx.com can accesible
xxx.com not blocked

 

1)
test url la-xxx.com

la-xxx.com adult-and-pornography (Dynamic db)

2)
test url xxx.com

xxx.com adult-and-pornography (Base db)


other info
----------

show url-cloud status

This command requires the PAN-DB URL filtering database.

url filtering db

5076

Thanks

 

 

8 REPLIES 8

L7 Applicator

Check your traffic logs to confirm what rule your session to these web sites is hitting.  I suspect that the rule that permits this traffic does not have the web filtering profile attached. 

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Hi,

I Made a mistake in my previous post, what  I mean xxx.com blocked at the same time la not blocked

Thanks

The same is true as already stated. Does the same policy control traffic to la-xxx.com as xxx.com. I'm going to guess that xxx.com is blocked because it has the url-filtering policy applied while the rule allowing access to la-xxx.com does not have the same url-filtering policy. Let us know if that isn't the case but that would be the first thing to look at. 

Hi,

 

" I'm going to guess that xxx.com is blocked because it has the url-filtering policy applied while the rule allowing access to la-xxx.com does not have the same url-filtering policy."

 

both is  going to the same rule 

 

Thanks

I would double check that your cache is actually displaying the proper results (test url-info-host la-xxx.com) and make sure that you are not using an old cache entry that labels it as something else. Short of that working I would try just clearing the cache all together and making it pull in new entries for everything. 

Hi,

 

I  tried the below 

test url-info-cloud la-xxx.xom

This command requires the PAN-DB URL filtering database.

What does it means 

Thanks

 

It sounds like you either are not using the PAN-DB and are using the BrightCloud database or you don't have an active license for URL-filtering anymore. 

L3 Networker

IF you are using Brightcloud try this via cli:

 

debug dataplane test url-resolve-path la-xxx.com

 

It will query locally first and, if unknown (not-resolved) it won't block it. The request will go out to the cloud for an update

 

URL la-xxx.com/, category is not-resolved, a request was sent successfully to the host

 

run it again:

 

debug dataplane test url-resolve-path la-xxx.com

 

it will come back classified correctly

 

URL la-xxx.com/, category adult-and-pornography

 

 

Larry

 

  • 3732 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!