Securing enterprise Internet access requires balancing productivity with defense against web-borne threats. Legacy packet filters cannot inspect web requests effectively. However, a structured Palo Alto URL filtering configuration enables granular control over outbound HTTP and HTTPS requests. This capability allows legitimate web traffic while blocking malware, phishing, and unwanted web content.
This technical guide provides a step-by-step tutorial for configuring Palo Alto Networks URL Filtering using PAN-DB. You will learn how to create security profiles, attach them to security policies, verify operational status, and troubleshoot real-world issues.
Real-Life Scenario
An enterprise organization, Apex Global Solutions (LAB/EXAMPLE), needs to enforce a corporate Internet usage policy for its users in the Trust zone. The security team established the following requirements:
- Block High-Risk Categories: Immediately block categories such as
phishing,malware,command-and-control,adult, andproxy-avoidance-and-anonymizers. - Control Productivity-Draining Categories: Warn users or restrict high-bandwidth and social media categories.
- Log Allowed Business Categories: Ensure business-related traffic (such as
business-and-economyandsearch-engines) generates explicit URL logs for audit compliance. - Custom Domain Exceptions: Allow specific external partner portals regardless of their default PAN-DB classification.
Lab Topology
The following diagram illustrates the network layout used in this guide. All IP addresses, hostnames, and interfaces represent a controlled lab environment.
+------------------------------------+
| Internal LAN Client |
| (LAB-Client / Trust) |
| IP: 192.0.2.100/24 |
+------------------------------------+
|
| [ethernet1/2]
+------------------------------------+
| Palo Alto Networks FW |
| (LAB-PA-FW01) |
| |
| PAN-OS: 10.2 / 11.0 |
| Service: PAN-DB URL Filtering |
+------------------------------------+
| [ethernet1/1]
|
+------------------------------------+
| Internet / WAN |
| Egress IP: 203.0.113.2 |
+------------------------------------+
Example Addressing and Objects
Use the following table as a reference for the objects and network parameters configured throughout this guide. Production environments must adapt these values to match local network designs.
| Object / Element | Type | Example Value (LAB) | Description |
|---|---|---|---|
Trust-Zone |
Security Zone | Layer 3 (ethernet1/2) | Internal corporate LAN network |
Untrust-Zone |
Security Zone | Layer 3 (ethernet1/1) | External Internet connection |
LAB-Client-Net |
Address Object | 192.0.2.0/24 | Subnet assigned to corporate users |
lab-custom-url-category |
Custom URL Category | *.partner-portal.example | Custom domain list for exception handling |
lab-url-profile-corporate |
URL Filtering Profile | Security Profile | Contains action maps for URL categories |
lab-rule-outbound-web |
Security Policy Rule | Trust to Untrust | Enforces security profile on outbound HTTP/HTTPS |
Prerequisites
Before implementing a URL filtering profile, confirm that the following operational requirements are met on the firewall:
- Active License: A valid PAN-DB URL Filtering feature license must be installed. Confirm this under Device > Licenses.
- Dynamic Updates: Up-to-date Application and Threat definitions are installed under Device > Dynamic Updates.
- DNS Resolution: The management interface or dataplane service route must resolve external DNS names to reach the PAN-DB cloud servers.
- SSL Decryption (Recommended): Without SSL Decryption, the firewall evaluates HTTPS requests using only the Server Name Indication (SNI) or the subject alternative name (SAN) in the server certificate. Full HTTP path inspection on HTTPS sessions requires an active SSL Forward Proxy Decryption policy.
Step-by-Step Palo Alto URL Filtering Configuration
Follow these steps to build a complete URL filtering policy. This setup creates a custom URL category, builds a URL filtering profile, applies actions, and attaches the profile to a security policy rule.
Step 1: Create a Custom URL Category
Custom URL categories allow you to define explicit domain matches that override standard PAN-DB categorization.
- Navigate to Objects > Custom Objects > URL Category.
- Click Add at the bottom of the window.
- In the Name field, enter
lab-custom-url-category. - Click Add in the Sites list and enter match patterns, such as
*.partner-portal.exampleorexample.com. - Click OK to save the object.
Step 2: Build the Security Profile for URL Filtering
The URL Filtering Profile defines the firewall’s action when a user attempts to access specific categories.
- Navigate to Objects > Security Profiles > URL Filtering.
- Click Add to create a new profile.
- Set the Name to
lab-url-profile-corporate. - Under the Categories tab, set explicit actions for categories based on policy requirements:
- Locate
phishing,malware,command-and-control,adult, andproxy-avoidance-and-anonymizers. Change their action fromallowtoblock. - Locate
social-networkingandstreaming-media. Set the action tocontinueoroverrideif user acknowledgement is required, or leave asalertto monitor. - Locate custom category
lab-custom-url-categoryand set its action toallow.
- Locate
- Important Setting: By default, categories set to
allowdo not generate logs. To log permitted web browsing, select standard business categories (or click Set Action Timeline / multi-select) and change the action fromallowtoalert.
Step 3: Configure User Response Pages (Optional)
When a block or continue action triggers, the firewall displays an HTTP response page to the user.
- Navigate to Device > Response Pages.
- Locate URL Filtering Block Page.
- Ensure the default response page is enabled or customize the HTML text to display support contact information.
Step 4: Attach the Profile to a Security Policy Rule
Security profiles take effect only when assigned to an active security policy rule allowing the traffic.
- Navigate to Policies > Security.
- Select an existing rule permitting outbound web traffic, or click Add to create
lab-rule-outbound-web. - Configure the following tabs:
- Source: Source Zone
Trust-Zone, Source AddressLAB-Client-Net(192.0.2.0/24). - Destination: Destination Zone
Untrust-Zone, Destination Addressany. - Application: Select
web-browsingandssl. - Service/URL Category: Keep Service as
application-default. - Actions: Set Action to
Allow.
- Source: Source Zone
- Under the Profile Setting section within the Actions tab:
- Set Profile Type to
Profiles. - Select
lab-url-profile-corporatein the URL Filtering drop-down menu.
- Set Profile Type to
- Click OK.
Step 5: Commit the Configuration
Changes in PAN-OS do not apply until committed to the active configuration.
- Click Commit at the top right of the Web Interface.
- Review the change summary and click Commit again.
CLI Configuration and Operational Commands
Network engineers often use the PAN-OS Command Line Interface (CLI) for rapid deployment or verification. Below are equivalent CLI syntax commands and operational tools.
Configuration Syntax Example
Enter configuration mode and run the following commands to create the profile and custom category:
configure
set profiles custom-url-category lab-custom-url-category list [ *.partner-portal.example example.com ]
set profiles url-filtering lab-url-profile-corporate block [ adult command-and-control malware phishing proxy-avoidance-and-anonymizers ]
set profiles url-filtering lab-url-profile-corporate alert [ business-and-economy search-engines shopping ]
set security rules lab-rule-outbound-web profile-setting profiles url-filtering lab-url-profile-corporate
commit
exit
Operational Verification Commands
Use these non-destructive commands in operational mode to test categorization and check service health:
1. Verify PAN-DB Cloud Connectivity:
show url-cloud status
2. Query Local Cache and Cloud Categorization for a URL:
test url www.example.com
3. Display Details of a Specific URL Filtering Profile:
show profile url-filtering lab-url-profile-corporate
How the Traffic Flows
Understanding the order of operations helps predict firewall behavior during URL evaluation:
[ Ingress Packet: TCP 80/443 ]
|
v
[ Zone / IP / Routing Lookup ]
|
v
[ Security Policy Match Check ]
- Rule allows traffic? ---> NO ---> [ Drop Packet ]
|
YES
v
[ App-ID Identification ]
- App: web-browsing / ssl
|
v
[ URL Category Inspection ]
1. Check Custom URL Categories (Highest Priority)
2. Check On-Box Local Cache
3. Query PAN-DB Cloud (If Cache Miss)
|
v
[ Evaluate Profile Action Map ]
+-------------------+--------------------+
| Block | Alert / Allow |
v v v
[ Drop + Block Page ] [ Generate Log ] [ Forward Packet ]
When an HTTP GET request or an HTTPS SSL/TLS Client Hello arrives:
- The firewall processes IP matching, routing, and security policy selection.
- The App-ID engine identifies the application as
web-browsing(HTTP) orssl(HTTPS). - The dataplane extracts the URL path (HTTP) or the Server Name Indication value (HTTPS).
- The URL is matched against custom URL categories first. If no custom category matches, the firewall checks its local PAN-DB cache, followed by a cloud query if necessary.
- The configured profile action applies:
- Block: Resets or drops the session and sends an HTTP block response page (if unencrypted or decrypted).
- Alert: Permits the connection and writes an entry to the URL Filtering log.
- Allow: Permits the connection without creating an explicit URL log entry.
Verification
After committing the configuration, test traffic enforcement using a test workstation (192.0.2.100).
1. GUI Log Verification
Navigate to Monitor > Logs > URL Filtering. Search for test sessions to verify category actions:
Filter string example:
( src eq 192.0.2.100 ) and ( action eq block )
Confirm that the log displays the correct Source User/IP, URL Category, and Action Taken (e.g., block-url or alert).
2. CLI Verification
Run the operational test command to verify how the engine classifies a specific web address:
admin@LAB-PA-FW01> test url www.paloaltonetworks.com
www.paloaltonetworks.com computer-and-internet-info (Base db) cloud fetch host: urlcloud.paloaltonetworks.com
This output proves that PAN-DB resolved the site successfully and returned the official category classification.
Troubleshooting
If URL filtering does not enforce rules as expected, use this logical workflow to locate the cause.
Symptom 1: Categories Match as “unrated”
- Cause: The firewall cannot reach the PAN-DB cloud service to query uncached URLs, or the URL license has expired.
- Check: Run
show url-cloud statusin the CLI. Confirm the status showsconnected. Check DNS settings on the management interface or service routes if state showsdisconnected.
Symptom 2: HTTPS Sites Are Not Blocked by Exact Path
- Cause: SSL Decryption is not configured. Without decryption, the firewall only inspects the SNI domain name during the TLS handshake. It cannot read the full HTTP request path (e.g.,
example.com/malicious/path). - Check: Verify whether an SSL Forward Proxy policy exists under Policies > Decryption. If decryption is not feasible, restrict policies using domain-level matching instead of sub-path patterns.
Symptom 3: Traffic Allowed Despite Being in a Blocked Category
- Cause: Security policy order issue. An earlier security policy rule without a URL filtering profile may be matching the traffic first.
- Check: Navigate to Monitor > Logs > Traffic. Identify the exact rule name processing the session. Reorder rules under Policies > Security so specific rules sit above broad permit rules.
Common Mistakes
Avoid these common misconfigurations when implementing URL filtering:
- Leaving Category Action set to Allow: The default action for category lists inside a profile is
allow. However,allowdoes not write entries to the URL log. Change actions toalertfor categories you want to log without blocking users. - Not Installing SSL Decryption: Attempting to block specific sub-pages on HTTPS sites without SSL Decryption will fail because the full URL path remains encrypted.
- Ignoring PAN-DB Cloud Reachability: Placing firewalls in restricted networks without granting out-of-band access to PAN-DB servers prevents live URL lookup updates.
- Overusing Custom Categories: Creating excessive custom categories for sites already classified properly by PAN-DB increases administrative overhead unnecessarily.
Production Considerations
When deploying URL filtering profiles into live enterprise networks, keep the following operational best practices in mind:
- Cloud Failure Response Mode: Configure how the firewall handles web traffic if PAN-DB becomes unreachable. Under Device > Setup > Content ID > URL Filtering, you can set the system default to allow or block traffic during cloud lookup timeouts. Most enterprises choose
allow(fail-open) to maintain business continuity. - User Override Setup: For sensitive corporate environments, use the
overrideaction instead of a hardblockfor non-malicious restriction categories. This requires users to enter a corporate password to temporarily bypass the block page. - Log Storage Capacity: Setting every URL category action to
alertgenerates a large volume of log records. Ensure local log storage or external syslog/Cortex Data Lake retention capacity is sized appropriately.
Related Palo Alto Guides
- Palo Alto security profiles
- Palo Alto destination NAT
- Palo Alto IPsec VPN troubleshooting
- Palo Alto Syslog/SIEM
Summary
A proper Palo Alto URL filtering configuration combines granular categorization, traffic visibility, and proactive threat prevention. By converting category actions from allow to alert, security administrators gain visibility into outbound web activity. Adding custom categories and attaching URL profiles to specific security policy rules ensures corporate compliance while blocking malicious content across the network.