Security policy match fails due to incorrect URL category classification.

Security policy match fails due to incorrect URL category classification.

130
Created On 01/25/26 17:49 PM - Last Modified 01/29/26 21:46 PM


Symptom


  • Security policy is configured with URL category match.
  • The traffic does not match the intended policy due to incorrect URL categorization.

Example:



Environment


  • PaloAlto firewall
  • Any PAN OS
  • No Decryption


Cause


  • Since decryption is not enabled, the Firewall does not have the complete visibility of the entire URL.
  • Only the SNI field can be checked without decryption enabled. This only has the main URL. In this case "https://urlfiltering.paloaltonetworks.com"
  • Since only partial URL is sent for categorization to the URL test site, the verdict received is "computer and internet info".


Resolution


  1. Enable Decryption.
  2. When decryption is enabled, the Firewall has the visibility of the entire URL which is sent to the Test Site.
  3. The test site correctly classifies the URL as "command-and-control"


Additional Information


If decryption is configured and still the reported URL category is incorrect, Follow steps documented at "How to Change an Incorrect PAN-DB URL Categorization".



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000wkNCKAY&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail