{"id":554,"date":"2026-08-17T10:12:18","date_gmt":"2026-08-17T04:42:18","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/palo-alto-url-filtering-configuration\/"},"modified":"2026-09-30T14:55:25","modified_gmt":"2026-09-30T09:25:25","slug":"palo-alto-url-filtering-configuration","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-url-filtering-configuration\/","title":{"rendered":"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example"},"content":{"rendered":"<p>Securing enterprise Internet access requires balancing productivity with defense against web-borne threats. Legacy packet filters cannot inspect web requests effectively. However, a structured <strong>Palo Alto URL filtering configuration<\/strong> enables granular control over outbound HTTP and HTTPS requests. This capability allows legitimate web traffic while blocking malware, phishing, and unwanted web content.<\/p>\n<p>This technical guide provides a step-by-step tutorial for configuring Palo Alto Networks URL Filtering using PAN-DB. You will learn how to create security profiles, attach them to security policies, verify operational status, and troubleshoot real-world issues.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>An enterprise organization, <strong>Apex Global Solutions (LAB\/EXAMPLE)<\/strong>, needs to enforce a corporate Internet usage policy for its users in the Trust zone. The security team established the following requirements:<\/p>\n<ul>\n<li><strong>Block High-Risk Categories:<\/strong> Immediately block categories such as <code>phishing<\/code>, <code>malware<\/code>, <code>command-and-control<\/code>, <code>adult<\/code>, and <code>proxy-avoidance-and-anonymizers<\/code>.<\/li>\n<li><strong>Control Productivity-Draining Categories:<\/strong> Warn users or restrict high-bandwidth and social media categories.<\/li>\n<li><strong>Log Allowed Business Categories:<\/strong> Ensure business-related traffic (such as <code>business-and-economy<\/code> and <code>search-engines<\/code>) generates explicit URL logs for audit compliance.<\/li>\n<li><strong>Custom Domain Exceptions:<\/strong> Allow specific external partner portals regardless of their default PAN-DB classification.<\/li>\n<\/ul>\n<h2>Lab Topology<\/h2>\n<p>The following diagram illustrates the network layout used in this guide. All IP addresses, hostnames, and interfaces represent a controlled lab environment.<\/p>\n<pre>\n+------------------------------------+\n|       Internal LAN Client          |\n|      (LAB-Client \/ Trust)          |\n|       IP: 192.0.2.100\/24           |\n+------------------------------------+\n                  |\n                  | [ethernet1\/2]\n+------------------------------------+\n|      Palo Alto Networks FW         |\n|      (LAB-PA-FW01)                 |\n|                                    |\n| PAN-OS: 10.2 \/ 11.0                |\n| Service: PAN-DB URL Filtering      |\n+------------------------------------+\n                  | [ethernet1\/1]\n                  |\n+------------------------------------+\n|         Internet \/ WAN             |\n|     Egress IP: 203.0.113.2         |\n+------------------------------------+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>Use the following table as a reference for the objects and network parameters configured throughout this guide. Production environments must adapt these values to match local network designs.<\/p>\n<table>\n<thead>\n<tr>\n<th>Object \/ Element<\/th>\n<th>Type<\/th>\n<th>Example Value (LAB)<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>Trust-Zone<\/code><\/td>\n<td>Security Zone<\/td>\n<td>Layer 3 (ethernet1\/2)<\/td>\n<td>Internal corporate LAN network<\/td>\n<\/tr>\n<tr>\n<td><code>Untrust-Zone<\/code><\/td>\n<td>Security Zone<\/td>\n<td>Layer 3 (ethernet1\/1)<\/td>\n<td>External Internet connection<\/td>\n<\/tr>\n<tr>\n<td><code>LAB-Client-Net<\/code><\/td>\n<td>Address Object<\/td>\n<td>192.0.2.0\/24<\/td>\n<td>Subnet assigned to corporate users<\/td>\n<\/tr>\n<tr>\n<td><code>lab-custom-url-category<\/code><\/td>\n<td>Custom URL Category<\/td>\n<td>*.partner-portal.example<\/td>\n<td>Custom domain list for exception handling<\/td>\n<\/tr>\n<tr>\n<td><code>lab-url-profile-corporate<\/code><\/td>\n<td>URL Filtering Profile<\/td>\n<td>Security Profile<\/td>\n<td>Contains action maps for URL categories<\/td>\n<\/tr>\n<tr>\n<td><code>lab-rule-outbound-web<\/code><\/td>\n<td>Security Policy Rule<\/td>\n<td>Trust to Untrust<\/td>\n<td>Enforces security profile on outbound HTTP\/HTTPS<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before implementing a URL filtering profile, confirm that the following operational requirements are met on the firewall:<\/p>\n<ul>\n<li><strong>Active License:<\/strong> A valid PAN-DB URL Filtering feature license must be installed. Confirm this under <strong>Device &gt; Licenses<\/strong>.<\/li>\n<li><strong>Dynamic Updates:<\/strong> Up-to-date Application and Threat definitions are installed under <strong>Device &gt; Dynamic Updates<\/strong>.<\/li>\n<li><strong>DNS Resolution:<\/strong> The management interface or dataplane service route must resolve external DNS names to reach the PAN-DB cloud servers.<\/li>\n<li><strong>SSL Decryption (Recommended):<\/strong> Without SSL Decryption, the firewall evaluates HTTPS requests using only the Server Name Indication (SNI) or the subject alternative name (SAN) in the server certificate. Full HTTP path inspection on HTTPS sessions requires an active SSL Forward Proxy Decryption policy.<\/li>\n<\/ul>\n<h2>Step-by-Step Palo Alto URL Filtering Configuration<\/h2>\n<p>Follow these steps to build a complete URL filtering policy. This setup creates a custom URL category, builds a URL filtering profile, applies actions, and attaches the profile to a security policy rule.<\/p>\n<h3>Step 1: Create a Custom URL Category<\/h3>\n<p>Custom URL categories allow you to define explicit domain matches that override standard PAN-DB categorization.<\/p>\n<ol>\n<li>Navigate to <strong>Objects &gt; Custom Objects &gt; URL Category<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> at the bottom of the window.<\/li>\n<li>In the <strong>Name<\/strong> field, enter <code>lab-custom-url-category<\/code>.<\/li>\n<li>Click <strong>Add<\/strong> in the Sites list and enter match patterns, such as <code>*.partner-portal.example<\/code> or <code>example.com<\/code>.<\/li>\n<li>Click <strong>OK<\/strong> to save the object.<\/li>\n<\/ol>\n<h3>Step 2: Build the Security Profile for URL Filtering<\/h3>\n<p>The URL Filtering Profile defines the firewall&#8217;s action when a user attempts to access specific categories.<\/p>\n<ol>\n<li>Navigate to <strong>Objects &gt; Security Profiles &gt; URL Filtering<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> to create a new profile.<\/li>\n<li>Set the <strong>Name<\/strong> to <code>lab-url-profile-corporate<\/code>.<\/li>\n<li>Under the <strong>Categories<\/strong> tab, set explicit actions for categories based on policy requirements:\n<ul>\n<li>Locate <code>phishing<\/code>, <code>malware<\/code>, <code>command-and-control<\/code>, <code>adult<\/code>, and <code>proxy-avoidance-and-anonymizers<\/code>. Change their action from <code>allow<\/code> to <code>block<\/code>.<\/li>\n<li>Locate <code>social-networking<\/code> and <code>streaming-media<\/code>. Set the action to <code>continue<\/code> or <code>override<\/code> if user acknowledgement is required, or leave as <code>alert<\/code> to monitor.<\/li>\n<li>Locate custom category <code>lab-custom-url-category<\/code> and set its action to <code>allow<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Important Setting:<\/strong> By default, categories set to <code>allow<\/code> do not generate logs. To log permitted web browsing, select standard business categories (or click <strong>Set Action Timeline<\/strong> \/ multi-select) and change the action from <code>allow<\/code> to <code>alert<\/code>.<\/li>\n<\/ol>\n<h3>Step 3: Configure User Response Pages (Optional)<\/h3>\n<p>When a block or continue action triggers, the firewall displays an HTTP response page to the user.<\/p>\n<ol>\n<li>Navigate to <strong>Device &gt; Response Pages<\/strong>.<\/li>\n<li>Locate <strong>URL Filtering Block Page<\/strong>.<\/li>\n<li>Ensure the default response page is enabled or customize the HTML text to display support contact information.<\/li>\n<\/ol>\n<h3>Step 4: Attach the Profile to a Security Policy Rule<\/h3>\n<p>Security profiles take effect only when assigned to an active security policy rule allowing the traffic.<\/p>\n<ol>\n<li>Navigate to <strong>Policies &gt; Security<\/strong>.<\/li>\n<li>Select an existing rule permitting outbound web traffic, or click <strong>Add<\/strong> to create <code>lab-rule-outbound-web<\/code>.<\/li>\n<li>Configure the following tabs:\n<ul>\n<li><strong>Source:<\/strong> Source Zone <code>Trust-Zone<\/code>, Source Address <code>LAB-Client-Net<\/code> (192.0.2.0\/24).<\/li>\n<li><strong>Destination:<\/strong> Destination Zone <code>Untrust-Zone<\/code>, Destination Address <code>any<\/code>.<\/li>\n<li><strong>Application:<\/strong> Select <code>web-browsing<\/code> and <code>ssl<\/code>.<\/li>\n<li><strong>Service\/URL Category:<\/strong> Keep Service as <code>application-default<\/code>.<\/li>\n<li><strong>Actions:<\/strong> Set Action to <code>Allow<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Profile Setting<\/strong> section within the <strong>Actions<\/strong> tab:\n<ul>\n<li>Set <strong>Profile Type<\/strong> to <code>Profiles<\/code>.<\/li>\n<li>Select <code>lab-url-profile-corporate<\/code> in the <strong>URL Filtering<\/strong> drop-down menu.<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 5: Commit the Configuration<\/h3>\n<p>Changes in PAN-OS do not apply until committed to the active configuration.<\/p>\n<ol>\n<li>Click <strong>Commit<\/strong> at the top right of the Web Interface.<\/li>\n<li>Review the change summary and click <strong>Commit<\/strong> again.<\/li>\n<\/ol>\n<h2>CLI Configuration and Operational Commands<\/h2>\n<p>Network engineers often use the PAN-OS Command Line Interface (CLI) for rapid deployment or verification. Below are equivalent CLI syntax commands and operational tools.<\/p>\n<h3>Configuration Syntax Example<\/h3>\n<p>Enter configuration mode and run the following commands to create the profile and custom category:<\/p>\n<pre><code>configure\nset profiles custom-url-category lab-custom-url-category list [ *.partner-portal.example example.com ]\nset profiles url-filtering lab-url-profile-corporate block [ adult command-and-control malware phishing proxy-avoidance-and-anonymizers ]\nset profiles url-filtering lab-url-profile-corporate alert [ business-and-economy search-engines shopping ]\nset security rules lab-rule-outbound-web profile-setting profiles url-filtering lab-url-profile-corporate\ncommit\nexit<\/code><\/pre>\n<h3>Operational Verification Commands<\/h3>\n<p>Use these non-destructive commands in operational mode to test categorization and check service health:<\/p>\n<p><strong>1. Verify PAN-DB Cloud Connectivity:<\/strong><\/p>\n<pre><code>show url-cloud status<\/code><\/pre>\n<p><strong>2. Query Local Cache and Cloud Categorization for a URL:<\/strong><\/p>\n<pre><code>test url www.example.com<\/code><\/pre>\n<p><strong>3. Display Details of a Specific URL Filtering Profile:<\/strong><\/p>\n<pre><code>show profile url-filtering lab-url-profile-corporate<\/code><\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding the order of operations helps predict firewall behavior during URL evaluation:<\/p>\n<pre>\n[ Ingress Packet: TCP 80\/443 ]\n               |\n               v\n[ Zone \/ IP \/ Routing Lookup ]\n               |\n               v\n[ Security Policy Match Check ]\n   - Rule allows traffic? ---&gt; NO ---&gt; [ Drop Packet ]\n               |\n              YES\n               v\n[ App-ID Identification ]\n   - App: web-browsing \/ ssl\n               |\n               v\n[ URL Category Inspection ]\n   1. Check Custom URL Categories (Highest Priority)\n   2. Check On-Box Local Cache\n   3. Query PAN-DB Cloud (If Cache Miss)\n               |\n               v\n[ Evaluate Profile Action Map ]\n   +-------------------+--------------------+\n   | Block             | Alert \/ Allow      |\n   v                   v                    v\n[ Drop + Block Page ]  [ Generate Log ]  [ Forward Packet ]\n<\/pre>\n<p>When an HTTP GET request or an HTTPS SSL\/TLS Client Hello arrives:<\/p>\n<ol>\n<li>The firewall processes IP matching, routing, and security policy selection.<\/li>\n<li>The App-ID engine identifies the application as <code>web-browsing<\/code> (HTTP) or <code>ssl<\/code> (HTTPS).<\/li>\n<li>The dataplane extracts the URL path (HTTP) or the Server Name Indication value (HTTPS).<\/li>\n<li>The URL is matched against custom URL categories first. If no custom category matches, the firewall checks its local PAN-DB cache, followed by a cloud query if necessary.<\/li>\n<li>The configured profile action applies:\n<ul>\n<li><strong>Block:<\/strong> Resets or drops the session and sends an HTTP block response page (if unencrypted or decrypted).<\/li>\n<li><strong>Alert:<\/strong> Permits the connection and writes an entry to the URL Filtering log.<\/li>\n<li><strong>Allow:<\/strong> Permits the connection without creating an explicit URL log entry.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>After committing the configuration, test traffic enforcement using a test workstation (<code>192.0.2.100<\/code>).<\/p>\n<h3>1. GUI Log Verification<\/h3>\n<p>Navigate to <strong>Monitor &gt; Logs &gt; URL Filtering<\/strong>. Search for test sessions to verify category actions:<\/p>\n<p>Filter string example:<\/p>\n<pre><code>( src eq 192.0.2.100 ) and ( action eq block )<\/code><\/pre>\n<p>Confirm that the log displays the correct <strong>Source User\/IP<\/strong>, <strong>URL Category<\/strong>, and <strong>Action Taken<\/strong> (e.g., <code>block-url<\/code> or <code>alert<\/code>).<\/p>\n<h3>2. CLI Verification<\/h3>\n<p>Run the operational test command to verify how the engine classifies a specific web address:<\/p>\n<pre><code>admin@LAB-PA-FW01&gt; test url www.paloaltonetworks.com\n\nwww.paloaltonetworks.com computer-and-internet-info (Base db) cloud fetch host: urlcloud.paloaltonetworks.com<\/code><\/pre>\n<p>This output proves that PAN-DB resolved the site successfully and returned the official category classification.<\/p>\n<h2>Troubleshooting<\/h2>\n<p>If URL filtering does not enforce rules as expected, use this logical workflow to locate the cause.<\/p>\n<h3>Symptom 1: Categories Match as &#8220;unrated&#8221;<\/h3>\n<ul>\n<li><strong>Cause:<\/strong> The firewall cannot reach the PAN-DB cloud service to query uncached URLs, or the URL license has expired.<\/li>\n<li><strong>Check:<\/strong> Run <code>show url-cloud status<\/code> in the CLI. Confirm the status shows <code>connected<\/code>. Check DNS settings on the management interface or service routes if state shows <code>disconnected<\/code>.<\/li>\n<\/ul>\n<h3>Symptom 2: HTTPS Sites Are Not Blocked by Exact Path<\/h3>\n<ul>\n<li><strong>Cause:<\/strong> SSL Decryption is not configured. Without decryption, the firewall only inspects the SNI domain name during the TLS handshake. It cannot read the full HTTP request path (e.g., <code>example.com\/malicious\/path<\/code>).<\/li>\n<li><strong>Check:<\/strong> Verify whether an SSL Forward Proxy policy exists under <strong>Policies &gt; Decryption<\/strong>. If decryption is not feasible, restrict policies using domain-level matching instead of sub-path patterns.<\/li>\n<\/ul>\n<h3>Symptom 3: Traffic Allowed Despite Being in a Blocked Category<\/h3>\n<ul>\n<li><strong>Cause:<\/strong> Security policy order issue. An earlier security policy rule without a URL filtering profile may be matching the traffic first.<\/li>\n<li><strong>Check:<\/strong> Navigate to <strong>Monitor &gt; Logs &gt; Traffic<\/strong>. Identify the exact rule name processing the session. Reorder rules under <strong>Policies &gt; Security<\/strong> so specific rules sit above broad permit rules.<\/li>\n<\/ul>\n<h2>Common Mistakes<\/h2>\n<p>Avoid these common misconfigurations when implementing URL filtering:<\/p>\n<ul>\n<li><strong>Leaving Category Action set to Allow:<\/strong> The default action for category lists inside a profile is <code>allow<\/code>. However, <code>allow<\/code> does not write entries to the URL log. Change actions to <code>alert<\/code> for categories you want to log without blocking users.<\/li>\n<li><strong>Not Installing SSL Decryption:<\/strong> Attempting to block specific sub-pages on HTTPS sites without SSL Decryption will fail because the full URL path remains encrypted.<\/li>\n<li><strong>Ignoring PAN-DB Cloud Reachability:<\/strong> Placing firewalls in restricted networks without granting out-of-band access to PAN-DB servers prevents live URL lookup updates.<\/li>\n<li><strong>Overusing Custom Categories:<\/strong> Creating excessive custom categories for sites already classified properly by PAN-DB increases administrative overhead unnecessarily.<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>When deploying URL filtering profiles into live enterprise networks, keep the following operational best practices in mind:<\/p>\n<ul>\n<li><strong>Cloud Failure Response Mode:<\/strong> Configure how the firewall handles web traffic if PAN-DB becomes unreachable. Under <strong>Device &gt; Setup &gt; Content ID &gt; URL Filtering<\/strong>, you can set the system default to allow or block traffic during cloud lookup timeouts. Most enterprises choose <code>allow<\/code> (fail-open) to maintain business continuity.<\/li>\n<li><strong>User Override Setup:<\/strong> For sensitive corporate environments, use the <code>override<\/code> action instead of a hard <code>block<\/code> for non-malicious restriction categories. This requires users to enter a corporate password to temporarily bypass the block page.<\/li>\n<li><strong>Log Storage Capacity:<\/strong> Setting every URL category action to <code>alert<\/code> generates a large volume of log records. Ensure local log storage or external syslog\/Cortex Data Lake retention capacity is sized appropriately.<\/li>\n<\/ul>\n<h2>Related Palo Alto Guides<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-profiles-configuration\/\">Palo Alto security profiles<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-destination-nat-configuration\/\">Palo Alto destination NAT<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-ipsec-vpn-troubleshooting\/\">Palo Alto IPsec VPN troubleshooting<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-log-forwarding-syslog-siem\/\">Palo Alto Syslog\/SIEM<\/a><\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>A proper Palo Alto URL filtering configuration combines granular categorization, traffic visibility, and proactive threat prevention. By converting category actions from allow to alert, security administrators gain visibility into outbound web activity. Adding custom categories and attaching URL profiles to specific security policy rules ensures corporate compliance while blocking malicious content across the network.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn Palo Alto URL filtering configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":553,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[5],"tags":[29,73,32,90,31,91],"class_list":["post-554","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-palo","tag-firewall-tutorial","tag-intermediate","tag-palo-alto-networks","tag-palo-alto-url-filtering-configuration","tag-pan-os","tag-url-filtering"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Palo Alto URL Filtering: Corporate Internet Access Guide<\/title>\n<meta name=\"description\" content=\"Configure Palo Alto URL filtering for corporate Internet access, including security profiles, policy attachment, testing and troubleshooting.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-url-filtering-configuration\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example\" \/>\n<meta property=\"og:description\" content=\"Configure Palo Alto URL filtering for corporate Internet access, including security profiles, policy attachment, testing and troubleshooting.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-url-filtering-configuration\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-17T04:42:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T09:25:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example\",\"datePublished\":\"2026-08-17T04:42:18+00:00\",\"dateModified\":\"2026-09-30T09:25:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/\"},\"wordCount\":1627,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png\",\"keywords\":[\"Firewall Tutorial\",\"Intermediate\",\"Palo Alto Networks\",\"Palo Alto URL filtering configuration\",\"PAN-OS\",\"URL Filtering\"],\"articleSection\":[\"Palo Alto\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/\",\"name\":\"Palo Alto URL Filtering: Corporate Internet Access Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png\",\"datePublished\":\"2026-08-17T04:42:18+00:00\",\"dateModified\":\"2026-09-30T09:25:25+00:00\",\"description\":\"Configure Palo Alto URL filtering for corporate Internet access, including security profiles, policy attachment, testing and troubleshooting.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png\",\"width\":1600,\"height\":900,\"caption\":\"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-url-filtering-configuration\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Palo Alto URL Filtering: Corporate Internet Access Guide","description":"Configure Palo Alto URL filtering for corporate Internet access, including security profiles, policy attachment, testing and troubleshooting.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-url-filtering-configuration\/","og_locale":"en_US","og_type":"article","og_title":"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example","og_description":"Configure Palo Alto URL filtering for corporate Internet access, including security profiles, policy attachment, testing and troubleshooting.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-url-filtering-configuration\/","og_site_name":"NetworkFix","article_published_time":"2026-08-17T04:42:18+00:00","article_modified_time":"2026-09-30T09:25:25+00:00","og_image":[{"width":1600,"height":900,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png","type":"image\/png"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example","datePublished":"2026-08-17T04:42:18+00:00","dateModified":"2026-09-30T09:25:25+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/"},"wordCount":1627,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png","keywords":["Firewall Tutorial","Intermediate","Palo Alto Networks","Palo Alto URL filtering configuration","PAN-OS","URL Filtering"],"articleSection":["Palo Alto"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/","url":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/","name":"Palo Alto URL Filtering: Corporate Internet Access Guide","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png","datePublished":"2026-08-17T04:42:18+00:00","dateModified":"2026-09-30T09:25:25+00:00","description":"Configure Palo Alto URL filtering for corporate Internet access, including security profiles, policy attachment, testing and troubleshooting.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-url-filtering-configuration-with-a-corporate-internet-access-example-featured.png","width":1600,"height":900,"caption":"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"Palo Alto URL Filtering Configuration with a Corporate Internet Access Example"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=554"}],"version-history":[{"count":2,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/554\/revisions"}],"predecessor-version":[{"id":1630,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/554\/revisions\/1630"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/553"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}