Why Palo Alto Networks URL filtering test site is categorized not as "proxy-avoidance-and-anonymizers" but "computer-and-internet-info" wrongly?

Why Palo Alto Networks URL filtering test site is categorized not as "proxy-avoidance-and-anonymizers" but "computer-and-internet-info" wrongly?

3529
Created On 09/27/24 07:18 AM - Last Modified 04/14/25 23:43 PM


Question


When the following URL filtering test site is accessed, it is not identified as the correct category.

urlfiltering.paloaltonetworks.com/test-Proxy-Avoidance-and-Anonymizers/

It should be identified as "proxy-avoidance-and-anonymizers", but becomes "computer-and-internet-info".
 


Environment


  • PAN-OS 10.1, 10.2, 11.0, 11.1, 11.2
  • URL filtering


Answer


When the URL is accessed normally with a browser, HTTPS is used instead of HTTP.

Since recent browsers no longer display "http://" or "https://" in the address bar,  it's difficult to distinguish which way is used. 

 

{Arress bar in Google Chrome]

 

When the URL is accessed with HTTPS, the URL field included in the "HTTP GET" is encrypted and the Next-Generation Firewall is not able to determine this.

In that case, the Next-Generation Firewall refers to the SNI(Server Name Indication) field included in the SSL Client Hello.

However, the SNI field only describes the hostname. 

 

[Client Hello capture decode on Wireshark]

 

As a result, the hostname "urlfiltering.paloaltonetworks.com" is categorized as "computer-and-internet-info".

If you use the URL Filtering test page, please access using the full URL including "http://" or enable the Decryption feature.

 



Additional Information


The following article contains links with full URLs including "http://", which can be useful for testing URL categories.
Please refer to the following article for SSL decryption configuration.

Please refer to this article for SSL decryption configuration.
How to Configure SSL Decryption

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000TpC4CAK&lang=es&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language