Why is Application Block Page not displayed for the blocked session of "web-browsing" App-ID?

Why is Application Block Page not displayed for the blocked session of "web-browsing" App-ID?

23574
Created On 07/13/21 04:14 AM - Last Modified 02/15/24 03:25 AM


Question


Why is Application Block Page not displayed for the blocked session of "web-browsing" App-ID?
Details
  • Action for "Application Block Page" is set to "Enabled"
  • Security Policy is configured to deny "web-browsing" or "SSL" traffic
  • The "Response pages" are no displayed in client's Web Browser when the clients access to the external servers via HTTP or HTTPS,
  • This happens even though the target traffic is denied by the configured Security Policy based on the application classification.


Environment


  • Palo Alto Firewalls
  • Supported PAN-OS
  • Application Block Page Enabled
  • Security Policy targeting the "web-browsing" or "ssl" traffic is configured with "Deny" or "Drop" Action.


Answer


  1. Application Block Page works for the applications that needs CTD (Content-ID Decoder) inspection
  2. "Web-browsing" or "SSL" application is classified earlier than the transaction in CTD. 
  3.  Hence when a security policy to deny or drop "web-browsing" or "SSL" traffic is configured, the corresponding traffic would be blocked before CTD inspection.
  4. Thus the Application Block Page is not displayed for that denied session. 
  5. For the application block page to work, deny the actual application (such as facebook) in the policy instead of blocking "web-browsing" or "SSL"


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oMJeCAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language