Learn how to customize the URL Filtering response pages
that display when users access sites in URL categories with block,
continue, or override policy actions.
Where can I use
What do I need?
Advanced URL Filtering license (or a legacy URL filtering
Legacy URL filtering licenses are discontinued,
but active legacy licenses are still
Prisma Access licenses usually include Advanced
URL Filtering capabilities.
By default, the URL filtering response pages explain why a
requested URL can't be accessed and show the user's IP address, the requested URL,
and the URL category. You can customize the response pages to meet the needs of your
enterprise. For example, you can change the message displayed to users, add
corporate branding, or link to an acceptable use policy.
To customize a response page, export it from a platform and modify it in a text
editor. You can make updates using the provided response page variables and references.
Response page variables correspond to the specific user, URL, and category that was
blocked. Response page references enable the use of images, sounds, style sheets,
Custom response pages larger than the maximum supported size are not decrypted or displayed to
users. In PAN-OS 8.1.2 and earlier PAN-OS 8.1 releases, custom response pages on
a decrypted site can't exceed 8,191 bytes; the maximum size is 17,999 bytes in
PAN-OS 8.1.3 and later releases.
Make sure that the page retains its UTF-8
encoding. For example, in Notepad you would select
drop-down in the Save As
Import the customized response page.
of response page you customized.
A dialog for the specific response page appears.
, and then click
. A file selection dialog appears. For
the file you customized or enter the file path.
, select the
virtual system that will use the response page, or select
to make it available to all virtual
, and then
Save the customized response page.
Verify that the customized response page displays.
From a web browser, visit a URL that will trigger the response page. For
example, to verify a customized URL Filtering and Category Match response
page, visit a URL blocked by your Security policy rules.
The firewall uses the following ports to display the URL filtering response