Panorama URL Filtering Test

URL filtering is a technique used to control or restrict access to websites based on a specific criteria. URL filtering enables category-based filtering of web traffic. Continuous monitoring of URL filters is essential for maintaining security, compliance, and efficient network operations. Incorrectly configured filters or outdated policies can lead to performance issues. The Panorama URL Filtering test helps the administrators in this regard!

This test continuously monitors the URL filters in the target panorama and reports the number of recent threats filtered by each URL filter. Using this test, administrators will be aware of threats from malicious websites and phishing sites.

Target of the test: Palo Alto Panorama

Agent deploying the test: A Remote Agent

Outputs of the test: One set of results for each URL filter in the Palo Alto Panorama that is being monitored.

Configurable parameters for the test

Parameter

Description

Test period

How often should the test be executed.

Host

The IP address of the target host to be monitored.

Port

Specify the port at which the specified host listens to.

API Key

The eG agent collects the required metrics from the target Palo Alto Panorama by executing API commands using XML API and pulls out critical metrics. In order to collect metrics, the eG agent should be provided with a valid API key.

SSL

By default, this flag is set to Yes indicating that the SSL (Secured Socket Layer) is used to connect to the target Palo Alto Panorama. If not so, set the SSL flag to No .

Detailed Diagnosis

To make diagnosis more efficient and accurate, the eG Enterprise embeds an optional detailed diagnostic capability. With this capability, the eG agents can be configured to run detailed, more elaborate tests as and when specific problems are detected. To enable the detailed diagnosis capability of this test for a particular server, choose the On option. To disable the capability, click on the Off option.

The option to selectively enable/disable the detailed diagnosis capability will be available only if the following conditions are fulfilled:

  • The eG manager license should allow the detailed diagnosis capability
  • Both the normal and abnormal frequencies configured for the detailed diagnosis measures should not be 0.
Measurements made by the test

Measurement

Description

Measurement Unit

Interpretation

Recent URL filters

Indicates the number of threats detected by this URL filter in the panorama.

Number

The detailed diagnosis of this measure lists the name/ID of the threat, severity, filename, application name, source/destination address, and source/destination port.