Examples of using wildcards in URL filtering profiles

Examples of using wildcards in URL filtering profiles

405206
Created On 05/19/21 04:20 AM - Last Modified 09/18/26 19:02 PM


Symptom


The article helps understand why certain URL is matching or not matching a wildcard filter in customer URL category.
Example: google.com in the URL category is matching google.com.randomwebsite.com


Environment


  • Palo Alto Firewall.
  • PAN-OS 8.1, 9.0, 9.1, 10.0, 10.1 , 10.2 , 11.1 , 11.2 , 12.1 
  • URL Filtering.


Resolution


Below are examples of how various wildcard filter combinations are matching and not matching particular websites according to current expected behavior:

  1.  *.google.com     - will match blog1.blog2.google.com.au.us. and will also match blog1.google.com (without / character there is an implicit * at the end)
  2.  ^.google.com/   - will match only blog.google.com but will not match google.com or other.blog.google.com
  3.  google.^              - will match any website on the right. Will match google.com, google.com.au, google.com.au.us
  4.  google.^.au/    - will match only google.com.au and google.uk.au but will not match google.com or google.com.au.website.info
  5.  *.google.com/   - will match blog1.blog2.google.com but will not match google.com or blog.google.com.au 
  6.  *.google.com.* - will match blog1.blog2.google.com.au.us and will not match blog1.google.com
  7.  google.com          - will match google.com.au and google.com.au.website and google.com
  8.  google.com/        - will match only google.com
  9. *.google.^ - will match any URL that has one or more subdomains - blog.google.com, blog1.blog2.google.com and will not match google.com or google.com.au
  10. *.google.co.^  - will match blog.google.co.uk , blog1,blog2.google.co.jp, blog.google.co.uk.au and will not match google.co.uk , blog.google.co 
  11.  All domain/subdomain patterns also would match all subpages that are related to these domains.
  12.  * and ^ can't be used in the same configuration on the same firewall in 9.0 and 8.1, but can be used in PAN-OS 9.1 and 10.0 later.
  13. Subpages can be matched by filter only if decryption is enabled for specific URLs.
    •  xyz.com/* - will match xyz.com/word1 and xyz.com/word2
    • or xyz.com/word. - will only match xyz.com/word


Additional Information


In PAN-OS 10.2+, the firewall will automatically append a trailing slash (/) to domain entries that do not end in a trailing slash (/) or asterisk (*). This is explained here:
TechDocs > Advanced URL Filtering > Guidelines for URL Category Exceptions



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oM79CAE&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language