Why Palo Alto Networks URL filtering test site is categorized not as "proxy-avoidance-and-anonymizers" but "computer-and-internet-info" wrongly?

Why Palo Alto Networks URL filtering test site is categorized not as "proxy-avoidance-and-anonymizers" but "computer-and-internet-info" wrongly?

3419
Created On 09/27/24 07:18 AM - Last Modified 04/14/25 23:43 PM


Question


 


Environment


  • PAN-OS 10.1, 10.2, 11.0, 11.1, 11.2
  • URL filtering


Answer


  1. When the URL is accessed normally with a browser, HTTPS is used instead of HTTP.
  2. Since recent browsers no longer display "http://" or "https://" in the address bar,  it's difficult to distinguish which way is used. 

{Acess bar in Google Chrome]

  1. When the URL is accessed with HTTPS, the URL field included in the "HTTP GET" is encrypted and the Firewall is not able to determine this.
  2. In that case, the Next-Generation Firewall refers to the SNI(Server Name Indication) field included in the SSL Client Hello.
  3. The SNI field only describes the hostname. Refer to the wireshark info below.
  4. As a result, the hostname "urlfiltering.paloaltonetworks.com" is categorized as "computer-and-internet-info".
  5. To use the URL Filtering test page, Use the full URL including "http://" or enable the Decryption feature.

[Client Hello capture decode on Wireshark]

 

 

 



Additional Information


 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000TpC4CAK&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language