Test URL Filtering Configuration

Follow these steps to verify that Palo Alto Networks URL Filtering services categorize and enforce policy on URLs as expected.
Where can I use this?
What do I need?
  • Prisma Access
  • PAN-OS
  • Advanced URL Filtering license
    For Prisma Access, this is usually included with your Prisma Access license.
To test your URL Filtering and Advanced URL Filtering policy configurations, use Palo Alto Networks URL Filtering Test Pages. Test pages have been created for the safe testing of all predefined URL categories, including real-time-detection categories applicable only to firewalls running Advanced URL Filtering.
You must enable SSL decryption for test pages to work over an HTTPS connection.
Advanced URL filtering test pages contain “real-time-detection” in the URL and confirm that firewalls correctly categorize and analyze malicious URLs in real-time. They do not verify firewall behavior for any other categories.
You can check the classification of a specific website using Palo Alto Networks URL category lookup tool, Test A Site.
Follow the procedure corresponding to your URL Filtering subscription:

Verify URL Filtering

If you have the legacy URL Filtering subscription, test and verify that the firewall correctly categorizes, enforces, and logs URLs in the categories that you access.
  1. Access a website in the URL category of interest.
    Consider testing sites in blocked URL categories. You can use a test page (urlfiltering.paloaltonetworks.com/test-
    ) to avoid directly accessing a site. For example, to test your block policy for malware, visit https://urlfiltering.paloaltonetworks.com/test-malware.
  2. Review the Traffic and URL Filtering logs to verify that your firewall processes the site correctly.
    For example, if you configured a block page to display when someone accesses a site that violates your organization’s policy, check that one appears when you visit the test site.

Verify Advanced URL Filtering

If you have an Advanced URL Filtering subscription, test and verify that real-time URL analysis is happening.
Palo Alto Networks recommends setting the real-time-detection action setting to alert for your active URL filtering profiles. This provides visibility into URLs analyzed in real-time and will block (or allow, depending on your policy settings) based on the category settings configured for specific web threats.
The firewall enforces the most severe action of the actions configured for detected URL categories of a given URL. For example, suppose example.com is categorized as real-time-detection, command-and-control, and shopping—categories with an alert, block, and allow action configured, respectively. The firewall will block the URL because block is the most severe action from the detected categories.
  1. Monitor web activity to verify that the tested URLs have been properly categorized as real-time-detection.
    1. Filter by
      (url_category_list contains real-time-detection)
      to view logs that have been analyzed using Advanced URL Filtering.
      Additional web page category matches are also displayed and corresponds to the categories as defined by PAN-DB.
    2. Take a detailed look at the logs to verify that each type of web threat is correctly analyzed and categorized.
      In the next example, the URL is categorized as having been analyzed in real-time and possessing qualities that define it as command-and-control (C2). Because the C2 category has a more severe action associated with it than real-time-detection (block as opposed to alert), the URL is categorized as command-and-control and blocked.

Recommended For You