URL filtering

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

URL filtering

L0 Member

Hi All,

Hope all doing good.

When i access one of internet website PA categorize as ssl/443-allowed and one of the user accessing the same website PA categorize it as web browsing/80 and is blocked/Threat.

Why is it behaving this way? Is this issue with website or from source side.

Can someone please explain?

Traffic log- 443/ssl allowed and 80/web browsing blocked

Url filter same behavior.

 

Thank you for your support.

 

4 REPLIES 4

L3 Networker

@Nizmytom 

 

What is the internet URL name?

Also what does threat log shows for TCP 80 traffic, how does it categorized (Malware, virus etc..)?

Do you see any threat log for TCP 443 traffic?

Is the traffic of both 443 and 80 hitting same rule?

If hitting different rules, does both rules have same security profile groups/threat profiles applied or is there any difference?

L1 Bithead

Are you sure the users are accessing the site using the same protocol, i.e. HTTP or HTTPS? Not all sites will redirect tcp/80 to tcp/443 but rather will answer on the  original port. This way one user may be accessing the site over HTTPS, while the other user over plain HTTP.

If you get "web browsing/80" as blocked/Threat

 

then I would look first at what it thinks is a threat,

 

otherwise if it's allowing "ssl/443" and your not doing SSL Decryption then the above threat may be getting through undetected.

This is the url: https://papirtigris.com/

We found it. It does not show us " categorize" is no solved. But its allowed in DC as well as branch but its not working only in branch so, we re-categorize it via cli and it started working.. But not sure why it did not show in traffic logs.

 

Thank you for all your help 🙂

 

  • 2774 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!