Multi-Category URL Filtering
PAN-DB classifies URLs with multiple categories, so that you can granularly control web access and how users interact with online content.
PAN-DB, the Palo Alto Networks URL database, now assigns multiple categories to URLs that classify a site’s content, purpose, and safety. Every URL now has up to four categories, including a risk category that indicates how likely it is that the site will expose you to threats. More granular URL categorizations means that you can move beyond a basic "block-or-allow" approach to web access. Instead, you can control how your users interact with online content that, while necessary for business, is more likely to be used as part of a cyberattack.
For instance, you might consider certain URL categories risky to your organization, but are hesitant to block them outright as they also provide valuable resources or services (like cloud storage services or blogs). Now, you can allow users to visit sites that fall into these types of URL categories, while also protecting your network by decrypting and inspecting traffic and enforcing read-only access to the content.
With multi-category URL Filtering, PAN-DB might classify a developer blog that your engineers use for research as:
If you’re already enforcing security policy based on URL categories, you will automatically start to benefit from multi-category URL Filtering after upgrading to PAN-OS 9.0.
Here’s what’s most important to know about multi-category URL Filtering, with some tips to get started:
- Multi-category URL Filtering requires a PAN-DB URL Filtering subscription. To confirm that the PAN-DB URL Filtering subscription license is active on the firewall, select DeviceLicenses).With an active license, the firewall connects to PAN-DB by default.
- You can Test A Site to see the categories that PAN-DB applies to URLs, and to learn about all the available URL categories.
- URL Filtering profiles now display your Custom URL Categories, External Dynamic URL Lists, and Pre-defined Categories (the PAN-DB categories) together, so that you can choose from these categories when defining policy for website access and usage.If you had configured URL Filtering overrides before upgrading to PAN-OS, your override block and allow lists are now converted to Custom URL Categories, and are displayed in this dropdown, too.More about this change: Release versions earlier than PAN-OS 9.0 allowed you to configure URL Filtering Overrides to create exceptions to URL category enforcement. In PAN-OS 9.0, the URL Filtering profile Overrides tab, where you would configure these block and allow lists, no longer exists. Any URL Filtering overrides that you configured before upgrading to PAN-OS 9.0 are now converted to custom URL Categories. If you had URL Filtering overrides configured before upgrading to PAN-OS 9.0, there are two issues that might impact you after upgrade. Review Upgrade/Downgrade Considerations to learn more, and for workarounds.
- You can define a custom URL category based on multiple PAN-DB URL categories. A new type of custom URL Category, Category Match, means that you can target enforcement for a website or page that matches a set of categories. The website or page must match all of the categories that you list. Here’s how to create custom URL categories.
- For websites or pages that hold more than one URL category, URL Filtering logs display the URL category with which the firewall based policy enforcement (the Category). URL Filtering logs also display all the URL categories for the site (the URL Category List).To view URL Filtering logs, select MonitorLogsURL Filtering and select any entry to learn more about the activity that triggered the log record.
- Where applicable, samples in AutoFocus show complete PAN-DB categorization details for each URL a sample connects to during WildFire analysis.To view the sample coverage details, select a sample hash in AutoFocus and then click the Coverage tab.
- To get started:
- Visit https://docs.paloaltonetworks.com/url-filtering.html for everything you need to know about URL Filtering.
- Follow the complete work flow to configure URL Filtering, and start enforcing security policy based on URL categories.
- Learn about the New Security-Focused URL Categories that allow you to control site access and how users interact with online content based on site safety.
New Security-Focused URL Categories
Use the new security-focused URL categories to implement simple security and decryption policies based on website safety, without requiring you to research and individually assess ...
URL Categories PAN-DB classifies websites based on site content, features, and safety. A URL can have up to four categories, including risk categories (high, medium, ...
Content Inspection Features
Learn about the new content inspection features introduced in PAN-OS 9.0. ...
Content Inspection Features
Describes all the exciting new content inspection capabilities in PAN-OS® 9.0. ...
Transition URL Filtering Profiles Safely to Best Practices
Apply URL Filtering profiles to allow rules to protect against risky websites and content without risking application availability. ...
Custom URL Categories
Custom URL Categories You can create a custom URL Filtering object to specify exceptions to URL category enforcement, and to create a custom URL category ...
Upgrade/Downgrade Considerations The following table lists the new features that have upgrade or downgrade impact. Make sure you understand all upgrade/downgrade considerations before you upgrade ...
URL Filtering Categories
URL Filtering Categories Select Objects Security Profiles URL Filtering Categories to control access to websites based on URL categories. Categories Settings Description Category Displays the ...
Determine URL Filtering Policy Requirements
Decide How You Want to Enforce URL Categories To first deploy URL filtering in your network, we recommend that you start with a basic setup ...