Securing enterprise Internet access requires balancing productivity with defense against web-borne threats. Legacy packet filters cannot inspect web requests effectively. However, a structured Palo Alto URL filtering configuration enables granular control over outbound HTTP and HTTPS requests. This capability allows legitimate web traffic while blocking malware, phishing, and unwanted web content.

This technical guide provides a step-by-step tutorial for configuring Palo Alto Networks URL Filtering using PAN-DB. You will learn how to create security profiles, attach them to security policies, verify operational status, and troubleshoot real-world issues.

Real-Life Scenario

An enterprise organization, Apex Global Solutions (LAB/EXAMPLE), needs to enforce a corporate Internet usage policy for its users in the Trust zone. The security team established the following requirements:

  • Block High-Risk Categories: Immediately block categories such as phishing, malware, command-and-control, adult, and proxy-avoidance-and-anonymizers.
  • Control Productivity-Draining Categories: Warn users or restrict high-bandwidth and social media categories.
  • Log Allowed Business Categories: Ensure business-related traffic (such as business-and-economy and search-engines) generates explicit URL logs for audit compliance.
  • Custom Domain Exceptions: Allow specific external partner portals regardless of their default PAN-DB classification.

Lab Topology

The following diagram illustrates the network layout used in this guide. All IP addresses, hostnames, and interfaces represent a controlled lab environment.

+------------------------------------+
|       Internal LAN Client          |
|      (LAB-Client / Trust)          |
|       IP: 192.0.2.100/24           |
+------------------------------------+
                  |
                  | [ethernet1/2]
+------------------------------------+
|      Palo Alto Networks FW         |
|      (LAB-PA-FW01)                 |
|                                    |
| PAN-OS: 10.2 / 11.0                |
| Service: PAN-DB URL Filtering      |
+------------------------------------+
                  | [ethernet1/1]
                  |
+------------------------------------+
|         Internet / WAN             |
|     Egress IP: 203.0.113.2         |
+------------------------------------+

Example Addressing and Objects

Use the following table as a reference for the objects and network parameters configured throughout this guide. Production environments must adapt these values to match local network designs.

Object / Element Type Example Value (LAB) Description
Trust-Zone Security Zone Layer 3 (ethernet1/2) Internal corporate LAN network
Untrust-Zone Security Zone Layer 3 (ethernet1/1) External Internet connection
LAB-Client-Net Address Object 192.0.2.0/24 Subnet assigned to corporate users
lab-custom-url-category Custom URL Category *.partner-portal.example Custom domain list for exception handling
lab-url-profile-corporate URL Filtering Profile Security Profile Contains action maps for URL categories
lab-rule-outbound-web Security Policy Rule Trust to Untrust Enforces security profile on outbound HTTP/HTTPS

Prerequisites

Before implementing a URL filtering profile, confirm that the following operational requirements are met on the firewall:

  • Active License: A valid PAN-DB URL Filtering feature license must be installed. Confirm this under Device > Licenses.
  • Dynamic Updates: Up-to-date Application and Threat definitions are installed under Device > Dynamic Updates.
  • DNS Resolution: The management interface or dataplane service route must resolve external DNS names to reach the PAN-DB cloud servers.
  • SSL Decryption (Recommended): Without SSL Decryption, the firewall evaluates HTTPS requests using only the Server Name Indication (SNI) or the subject alternative name (SAN) in the server certificate. Full HTTP path inspection on HTTPS sessions requires an active SSL Forward Proxy Decryption policy.

Step-by-Step Palo Alto URL Filtering Configuration

Follow these steps to build a complete URL filtering policy. This setup creates a custom URL category, builds a URL filtering profile, applies actions, and attaches the profile to a security policy rule.

Step 1: Create a Custom URL Category

Custom URL categories allow you to define explicit domain matches that override standard PAN-DB categorization.

  1. Navigate to Objects > Custom Objects > URL Category.
  2. Click Add at the bottom of the window.
  3. In the Name field, enter lab-custom-url-category.
  4. Click Add in the Sites list and enter match patterns, such as *.partner-portal.example or example.com.
  5. Click OK to save the object.

Step 2: Build the Security Profile for URL Filtering

The URL Filtering Profile defines the firewall’s action when a user attempts to access specific categories.

  1. Navigate to Objects > Security Profiles > URL Filtering.
  2. Click Add to create a new profile.
  3. Set the Name to lab-url-profile-corporate.
  4. Under the Categories tab, set explicit actions for categories based on policy requirements:
    • Locate phishing, malware, command-and-control, adult, and proxy-avoidance-and-anonymizers. Change their action from allow to block.
    • Locate social-networking and streaming-media. Set the action to continue or override if user acknowledgement is required, or leave as alert to monitor.
    • Locate custom category lab-custom-url-category and set its action to allow.
  5. Important Setting: By default, categories set to allow do not generate logs. To log permitted web browsing, select standard business categories (or click Set Action Timeline / multi-select) and change the action from allow to alert.

Step 3: Configure User Response Pages (Optional)

When a block or continue action triggers, the firewall displays an HTTP response page to the user.

  1. Navigate to Device > Response Pages.
  2. Locate URL Filtering Block Page.
  3. Ensure the default response page is enabled or customize the HTML text to display support contact information.

Step 4: Attach the Profile to a Security Policy Rule

Security profiles take effect only when assigned to an active security policy rule allowing the traffic.

  1. Navigate to Policies > Security.
  2. Select an existing rule permitting outbound web traffic, or click Add to create lab-rule-outbound-web.
  3. Configure the following tabs:
    • Source: Source Zone Trust-Zone, Source Address LAB-Client-Net (192.0.2.0/24).
    • Destination: Destination Zone Untrust-Zone, Destination Address any.
    • Application: Select web-browsing and ssl.
    • Service/URL Category: Keep Service as application-default.
    • Actions: Set Action to Allow.
  4. Under the Profile Setting section within the Actions tab:
    • Set Profile Type to Profiles.
    • Select lab-url-profile-corporate in the URL Filtering drop-down menu.
  5. Click OK.

Step 5: Commit the Configuration

Changes in PAN-OS do not apply until committed to the active configuration.

  1. Click Commit at the top right of the Web Interface.
  2. Review the change summary and click Commit again.

CLI Configuration and Operational Commands

Network engineers often use the PAN-OS Command Line Interface (CLI) for rapid deployment or verification. Below are equivalent CLI syntax commands and operational tools.

Configuration Syntax Example

Enter configuration mode and run the following commands to create the profile and custom category:

configure
set profiles custom-url-category lab-custom-url-category list [ *.partner-portal.example example.com ]
set profiles url-filtering lab-url-profile-corporate block [ adult command-and-control malware phishing proxy-avoidance-and-anonymizers ]
set profiles url-filtering lab-url-profile-corporate alert [ business-and-economy search-engines shopping ]
set security rules lab-rule-outbound-web profile-setting profiles url-filtering lab-url-profile-corporate
commit
exit

Operational Verification Commands

Use these non-destructive commands in operational mode to test categorization and check service health:

1. Verify PAN-DB Cloud Connectivity:

show url-cloud status

2. Query Local Cache and Cloud Categorization for a URL:

test url www.example.com

3. Display Details of a Specific URL Filtering Profile:

show profile url-filtering lab-url-profile-corporate

How the Traffic Flows

Understanding the order of operations helps predict firewall behavior during URL evaluation:

[ Ingress Packet: TCP 80/443 ]
               |
               v
[ Zone / IP / Routing Lookup ]
               |
               v
[ Security Policy Match Check ]
   - Rule allows traffic? ---> NO ---> [ Drop Packet ]
               |
              YES
               v
[ App-ID Identification ]
   - App: web-browsing / ssl
               |
               v
[ URL Category Inspection ]
   1. Check Custom URL Categories (Highest Priority)
   2. Check On-Box Local Cache
   3. Query PAN-DB Cloud (If Cache Miss)
               |
               v
[ Evaluate Profile Action Map ]
   +-------------------+--------------------+
   | Block             | Alert / Allow      |
   v                   v                    v
[ Drop + Block Page ]  [ Generate Log ]  [ Forward Packet ]

When an HTTP GET request or an HTTPS SSL/TLS Client Hello arrives:

  1. The firewall processes IP matching, routing, and security policy selection.
  2. The App-ID engine identifies the application as web-browsing (HTTP) or ssl (HTTPS).
  3. The dataplane extracts the URL path (HTTP) or the Server Name Indication value (HTTPS).
  4. The URL is matched against custom URL categories first. If no custom category matches, the firewall checks its local PAN-DB cache, followed by a cloud query if necessary.
  5. The configured profile action applies:
    • Block: Resets or drops the session and sends an HTTP block response page (if unencrypted or decrypted).
    • Alert: Permits the connection and writes an entry to the URL Filtering log.
    • Allow: Permits the connection without creating an explicit URL log entry.

Verification

After committing the configuration, test traffic enforcement using a test workstation (192.0.2.100).

1. GUI Log Verification

Navigate to Monitor > Logs > URL Filtering. Search for test sessions to verify category actions:

Filter string example:

( src eq 192.0.2.100 ) and ( action eq block )

Confirm that the log displays the correct Source User/IP, URL Category, and Action Taken (e.g., block-url or alert).

2. CLI Verification

Run the operational test command to verify how the engine classifies a specific web address:

admin@LAB-PA-FW01> test url www.paloaltonetworks.com

www.paloaltonetworks.com computer-and-internet-info (Base db) cloud fetch host: urlcloud.paloaltonetworks.com

This output proves that PAN-DB resolved the site successfully and returned the official category classification.

Troubleshooting

If URL filtering does not enforce rules as expected, use this logical workflow to locate the cause.

Symptom 1: Categories Match as “unrated”

  • Cause: The firewall cannot reach the PAN-DB cloud service to query uncached URLs, or the URL license has expired.
  • Check: Run show url-cloud status in the CLI. Confirm the status shows connected. Check DNS settings on the management interface or service routes if state shows disconnected.

Symptom 2: HTTPS Sites Are Not Blocked by Exact Path

  • Cause: SSL Decryption is not configured. Without decryption, the firewall only inspects the SNI domain name during the TLS handshake. It cannot read the full HTTP request path (e.g., example.com/malicious/path).
  • Check: Verify whether an SSL Forward Proxy policy exists under Policies > Decryption. If decryption is not feasible, restrict policies using domain-level matching instead of sub-path patterns.

Symptom 3: Traffic Allowed Despite Being in a Blocked Category

  • Cause: Security policy order issue. An earlier security policy rule without a URL filtering profile may be matching the traffic first.
  • Check: Navigate to Monitor > Logs > Traffic. Identify the exact rule name processing the session. Reorder rules under Policies > Security so specific rules sit above broad permit rules.

Common Mistakes

Avoid these common misconfigurations when implementing URL filtering:

  • Leaving Category Action set to Allow: The default action for category lists inside a profile is allow. However, allow does not write entries to the URL log. Change actions to alert for categories you want to log without blocking users.
  • Not Installing SSL Decryption: Attempting to block specific sub-pages on HTTPS sites without SSL Decryption will fail because the full URL path remains encrypted.
  • Ignoring PAN-DB Cloud Reachability: Placing firewalls in restricted networks without granting out-of-band access to PAN-DB servers prevents live URL lookup updates.
  • Overusing Custom Categories: Creating excessive custom categories for sites already classified properly by PAN-DB increases administrative overhead unnecessarily.

Production Considerations

When deploying URL filtering profiles into live enterprise networks, keep the following operational best practices in mind:

  • Cloud Failure Response Mode: Configure how the firewall handles web traffic if PAN-DB becomes unreachable. Under Device > Setup > Content ID > URL Filtering, you can set the system default to allow or block traffic during cloud lookup timeouts. Most enterprises choose allow (fail-open) to maintain business continuity.
  • User Override Setup: For sensitive corporate environments, use the override action instead of a hard block for non-malicious restriction categories. This requires users to enter a corporate password to temporarily bypass the block page.
  • Log Storage Capacity: Setting every URL category action to alert generates a large volume of log records. Ensure local log storage or external syslog/Cortex Data Lake retention capacity is sized appropriately.

Related Palo Alto Guides

Summary

A proper Palo Alto URL filtering configuration combines granular categorization, traffic visibility, and proactive threat prevention. By converting category actions from allow to alert, security administrators gain visibility into outbound web activity. Adding custom categories and attaching URL profiles to specific security policy rules ensures corporate compliance while blocking malicious content across the network.