Allowing outbound internet traffic based on IP addresses, ports, or even App-ID alone is not enough to protect an enterprise network. Malicious files, drive-by downloads, command-and-control (C2) beacons, and phishing sites frequently hide inside standard HTTP and HTTPS sessions. To secure internet access, you must apply layer-7 content inspection to permitted traffic.

This technical tutorial demonstrates how to configure and attach Palo Alto security profiles to internet access security policies. You will learn how individual security profiles function, how to group them efficiently using Security Profile Groups, and how to verify deep packet inspection in production.

Real-Life Scenario

Acme Corp has an active Security Policy rule allowing internal users in the Trust zone to access the Untrust zone using web-browsing and ssl applications. While traffic flows successfully, the security operations team has no threat visibility, content filtering, or file restrictions on these internet sessions.

The business requirement is to implement full content inspection without creating duplicate security rules. To achieve this, we will build custom security profiles for Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, File Blocking, and WildFire. We will then combine these profiles into a single Security Profile Group and attach it to the existing internet access policy.

Lab Topology

The following diagram outlines the enterprise topology used in this configuration guide:

+---------------------+           +----------------------------------+           +-------------------+
|  Internal Client    |           |    Palo Alto Networks Firewall   |           |  Internet Router  |
|  10.0.1.50/24       |-----------|  ethernet1/2        ethernet1/1  |-----------|  198.51.100.1     |
|  (Trust Zone)       |           |  10.0.1.1/24       203.0.113.2/24|           |  (Untrust Gateway)|
+---------------------+           +----------------------------------+           +-------------------+
                                            |
                                  +-------------------+
                                  | Palo Alto Cloud / |
                                  | WildFire Cloud    |
                                  +-------------------+

Example Addressing and Objects

The lab setup uses the following sample IP addresses, zones, and profile naming conventions. Adapt these values to match your enterprise naming standards.

Object / Element Name / Value Description
Trust Interface ethernet1/2 (10.0.1.1/24) Internal client gateway interface
Untrust Interface ethernet1/1 (203.0.113.2/24) External egress interface to ISP router (198.51.100.1)
Client Host 10.0.1.50 (LAB_CLIENT) Internal workstation generating outbound web traffic
Profile Group GRP-SEC-INTERNET-OUTBOUND Security Profile Group container for internet access
URL Profile PROF-URL-INTERNET Custom URL Filtering profile blocking dangerous categories
File Blocking Profile PROF-FB-INTERNET Custom File Blocking profile restricting high-risk extensions

Prerequisites

Before applying security profiles to an active security policy, ensure the following requirements are met:

  • Active Subscriptions: Threat Prevention, Advanced URL Filtering (or PAN-DB URL Filtering), and WildFire licenses must be installed and active.
  • Dynamic Updates: The firewall must have current Applications and Threats signatures along with Antivirus signatures installed under Device > Dynamic Updates.
  • SSL Decryption: Outbound SSL Forward Proxy decryption should be configured. Because over 80% of modern web traffic uses TLS, security profiles cannot inspect payload content, detect virus signatures, or block dangerous file downloads inside encrypted HTTPS sessions unless SSL Decryption is active.
  • Existing Security Policy: An active outbound security rule permitting traffic from the internal zone to the external zone.

Step-by-Step GUI Configuration

Applying threat inspection requires two main phases: creating or customizing individual security profiles, and attaching them to your security rules. Using Security Profile Groups simplifies management by allowing you to attach a single object to multiple rules.

Step 1: Review and Customize Individual Security Profiles

Navigate to Objects > Security Profiles in the web interface. While Palo Alto Networks supplies default profiles, customizing profiles for outbound internet access allows strict enforcement.

1. Antivirus Profile

Navigate to Objects > Security Profiles > Antivirus. Click Add to create a new profile named PROF-AV-INTERNET.

  • Set the action for HTTP, SMTP, IMAP, POP3, FTP, and SMB protocols to reset-both or block for viral signatures.
  • Enable WildFire Inline ML if your firewall supports PAN-OS 10.0 or later to detect zero-day executable threats in real time.

2. Anti-Spyware Profile

Navigate to Objects > Security Profiles > Anti-Spyware. Click Add to create PROF-AS-INTERNET.

  • Under the Rules tab, ensure high, critical, and medium severity threats are set to reset-both.
  • Under the DNS Security tab, set actions for known malicious domains, C2 domains, and phishing domains to block or sinkhole.
  • If using a sinkhole, set the IPv4 Sinkhole address to a non-routable loopback IP (for example, 192.0.2.254) to capture compromised host DNS queries.

3. Vulnerability Protection Profile

Navigate to Objects > Security Profiles > Vulnerability Protection. Click Add to create PROF-VP-INTERNET.

  • Configure rules to block client-side exploit attempts.
  • Set actions for Critical, High, and Medium severity vulnerabilities to reset-both.

4. URL Filtering Profile

Navigate to Objects > Security Profiles > URL Filtering. Click Add to create PROF-URL-INTERNET.

  • Set high-risk categories to block: malware, phishing, command-and-control, command-and-control-agent, and unknown.
  • Set questionable or non-work-related categories (e.g., adult, gambling) to block or continue based on organizational policy.
  • Under User HTTP Header Insertion or Credential Enforcement, adjust anti-phishing settings if required.

5. File Blocking Profile

Navigate to Objects > Security Profiles > File Blocking. Click Add to create PROF-FB-INTERNET.

  • Add a rule to block high-risk file types (such as exe, bat, vbs, dll, hqx, scr) for upload and download directions. Set the action to block.
  • Add a second rule to log encrypted file archives (such as encrypted-zip or encrypted-rar) by setting the action to continue or block.

6. WildFire Analysis Profile

Navigate to Objects > Security Profiles > WildFire Analysis. Click Add to create PROF-WF-INTERNET.

  • Add a rule setting File Types to any, Direction to both, and Analysis to public-cloud.

Step 2: Create a Security Profile Group

Combining individual profiles into a Security Profile Group prevents configuration administrative overhead and ensures consistency across multiple rules.

  1. Navigate to Objects > Security Profile Groups.
  2. Click Add at the bottom of the screen.
  3. Name the group: GRP-SEC-INTERNET-OUTBOUND.
  4. Select the profiles created in Step 1 from each drop-down menu:
    • Antivirus: PROF-AV-INTERNET
    • Anti-Spyware: PROF-AS-INTERNET
    • Vulnerability Protection: PROF-VP-INTERNET
    • URL Filtering: PROF-URL-INTERNET
    • File Blocking: PROF-FB-INTERNET
    • WildFire Analysis: PROF-WF-INTERNET
  5. Click OK.

Step 3: Attach the Profile Group to the Security Policy

Now attach the completed group object to your existing internet outbound security policy rule.

  1. Navigate to Policies > Security.
  2. Locate your outbound internet rule (for example, ALLOW-TRUST-TO-UNTRUST).
  3. Click the rule name to open the rule settings dialog.
  4. Select the Actions tab.
  5. Under the Profile Setting section, change the Profile Type drop-down menu from None (or Profiles) to Group.
  6. Select GRP-SEC-INTERNET-OUTBOUND from the Group Object drop-down list.
  7. Verify that Log at Session End is checked under Log Settings so threat logs generate correlation data.
  8. Click OK.
  9. Click Commit at the top right of the GUI to apply the changes to the active running configuration.

CLI Configuration and Verification Commands

Network engineers who prefer using the command-line interface can verify and review profile structures using operational commands.

To view the detailed contents of the newly configured Security Profile Group, run:

admin@PA-FW> show profile-group GRP-SEC-INTERNET-OUTBOUND

To inspect how profiles are attached to active security rules in the running configuration, use the following operational command:

admin@PA-FW> show running security-policy

To check threat engine status and ensure dynamic content signatures are loaded properly in system memory, run:

admin@PA-FW> show system setting threat

To monitor dynamic file submission status to the WildFire cloud via CLI, execute:

admin@PA-FW> show wildfire status

How the Traffic Flows

Understanding PAN-OS Single-Pass Parallel Processing (SP3) helps clarify how Palo Alto security profiles inspect traffic without adding high latency.

  1. Packet Arrival and Session Matching: A client at 10.0.1.50 initiates an outbound HTTP/HTTPS connection to an external site. The firewall checks ingress routing, zone evaluation, and matches the session against the security rule ALLOW-TRUST-TO-UNTRUST.
  2. App-ID Identification: The firewall inspects initial packets to identify the application (for example, web-browsing or ssl).
  3. SSL Decryption Processing: If the session is HTTPS and matches an SSL Forward Proxy decryption rule, the firewall decrypts the session payload. If SSL Decryption is omitted, payload inspection is bypassed for encrypted streams.
  4. Single-Pass Threat Inspection: Once the payload is accessible, PAN-OS executes hardware-accelerated parallel scanning across all profiles linked in the Security Profile Group simultaneously:
    • URL Engine: Evaluates the HTTP Host header, SNI, or URI request against URL category databases.
    • Antivirus & Anti-Spyware Engine: Matches streaming payload content against threat signatures.
    • File Blocking Engine: Inspects file magic bytes (headers) to enforce blocking rules regardless of file extension spoofing.
    • WildFire Engine: Identifies unknown zero-day executable files and forwards samples to the WildFire cloud for sandbox analysis.
  5. Enforcement Action: If any security profile detects a violation set to block or reset, the session is terminated immediately. A RST packet is sent to both client and server, or a custom block page is presented to the user. If all engines pass, the packet is forwarded to the gateway at 198.51.100.1.

Verification

After committing your changes, perform real-world checks to confirm security enforcement is operating correctly.

1. Testing Antivirus Profile Inspection

From an internal client, attempt to download the standard synthetic EICAR test file over plain HTTP:

curl -I http://www.eicar.org/download/eicar.com

Expected Result: The firewall blocks the download connection or returns an HTTP reset. In the web interface, navigate to Monitor > Logs > Threat and verify a log entry for Eicar-Test-Signature with an action of reset-both or block.

2. Testing URL Filtering Inspection

Open a web browser on an internal host and navigate to a known test domain provided by Palo Alto Networks:

http://test-url.paloaltonetworks.com/malware

Expected Result: The browser presents a Palo Alto Networks URL block page. Check Monitor > Logs > URL Filtering to confirm the entry shows category malware and action block-url.

3. Checking Log Details in the GUI

Open Monitor > Logs > Threat. Click the magnifying glass icon next to a threat event to review session metadata, including:

  • Source IP (10.0.1.50) and Destination IP.
  • Rule Name (ALLOW-TRUST-TO-UNTRUST).
  • Security Profile Object associated with the violation.
  • Specific threat ID, CVE number, or URL category.

Troubleshooting Profile Issues

When security profiles fail to inspect or block traffic as expected, review the following troubleshooting matrix:

Symptom Probable Root Cause Recommended Action / Check
Threats inside HTTPS connections are ignored. SSL Decryption is disabled or bypassed for that destination. Verify SSL Forward Proxy policy under Policies > Decryption. Ensure client trusts the enterprise CA certificate.
File blocking does not execute on renamed files (e.g., .exe renamed to .txt). Using basic file extensions instead of PAN-OS file types. Ensure File Blocking profile uses true file type identification (decoder engine) rather than simple string extension checks.
Security profiles are not generating threat logs. Logging at session end is disabled on the Security Policy rule. Edit the security rule under Policies > Security > Actions and verify Log at Session End is enabled.
URL category blocks are ignored for HTTPS sites. No SSL Decryption, or fallback to Server Certificate/SNI matching fails. Check if App-ID identifies traffic as ssl instead of web-browsing. Enable SSL Decryption for URL-based policy enforcement.

Common Mistakes

  • Forgetting SSL Decryption: Applying security profiles to encrypted HTTPS traffic without SSL Decryption renders Antivirus, Anti-Spyware, and File Blocking profiles ineffective against payloads. The firewall can only inspect unencrypted TLS headers.
  • Overreliance on Default Profiles: Relying solely on the built-in default profile without review can leave default alert actions active where block or reset should be enforced.
  • Attaching Profiles Individually: Assigning separate profiles to every rule manually creates configuration drift. Always aggregate profiles into Security Profile Groups.
  • Blocking Essential Update Traffic: Applying aggressive URL or file blocking rules to infrastructure subnets can break automated OS updates, software patches, or CRL revocation checks. Exclude operational update servers or apply dedicated management profile groups.

Production Considerations

Before rolling out new security profiles across large enterprise environments, keep these operational deployment recommendations in mind:

  • Use Alert-Only Phased Rollouts: When introducing new profile groups into an existing environment, set custom profile actions to alert for 1–2 weeks. Monitor Monitor > Logs > Threat and Monitor > Logs > URL Filtering to assess potential false positives before switching actions to block or reset-both.
  • Hardware Optimization and Capacity: Deep packet inspection relies heavily on dedicated hardware processing (Data Plane DP CPUs). Monitor system resource utilization via CLI using show running resource-monitor during peak operating hours when activating SSL Decryption alongside full threat prevention.
  • Custom Block Pages: Customize user block pages under Device > Response Pages. Providing clean error pages with helpdesk contact information significantly reduces support ticket resolution times when users encounter blocked URLs or files.

Related Palo Alto Guides

Summary

Applying layer-7 Palo Alto security profiles converts basic transport-layer access rules into comprehensive threat enforcement points. By configuring customized profiles for Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, File Blocking, and WildFire, you can stop modern threats before they cross your network perimeter.

Leveraging Security Profile Groups keeps security policies organized, while pairing profile inspection with SSL Forward Proxy Decryption ensures total visibility into encrypted outbound traffic.