Custom URL Categories are not Matching Correctly when URL Overlaps with Another Custom Category
48918
Created On 09/26/18 13:54 PM - Last Modified 07/28/21 22:50 PM
Symptom
Configurations with custom URL categories that match the same URLs can cause unpredictable results. With multiple custom URL categories that have overlapping regexes the URL will match multiple categories and an incorrect category may be chosen causing the wrong security policy to be used.
Environment
- Palo Alto Firewall.
- Any PAN-OS.
- URL Filtering Profile configured.
Resolution
Custom category URLs should not overlap with other custom categories. Regex patterns should be constructed so that only one category can match a given URL request.
Additional Information
Article original author: Richard Kim