URL games allowed through while blocked

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

URL games allowed through while blocked

L0 Member

HI Gang,

 

Fairly new palo user here 👋

 

I'm having a headache where I have configured URL filtering to block students from accessing games. I have decryption in place however they are freely accessing those games (the site is both categorized as low risk (alert) and games (block)). 

I've been reading forums and the block is supposed to take precedence, I have read I need decrypt which looks like that is the case, even more weird under Monitor | URL filtering the action is block-url, now I'm clearly missing something, can anyone suggest what that could be?

 

Rock on

 

(the query (url contains azgames.io), brings up that string under a google analytics URL, categorized as computer and internet) 

2 REPLIES 2

L4 Transporter

Hi @THall1415 ,

You may try with capturing the traffic to understand what is passing through from firewall and also revisit to your polices and decryption as if decryption is working correctly and contents are matching with existing security policy also check if you do have other security policies on top to configured polices which are allowing the access.

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/take-packet-captures

https://docs.paloaltonetworks.com/network-security/decryption/administration/decryption-overview

https://docs.paloaltonetworks.com/advanced-url-filtering/administration/configuring-url-filtering

 



Best Regards,
Mohammad Talib

L0 Member

An FYI, I found that it was down to the Quic protocol.

 

Blocked that at firewall level, also (so it wouldn't try and timeout) changed our policies for chrome and edge to disable Quic.

 

 

 

disabled in both edge and chrome as well as at 

 

 

  • 384 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!