A knowledge base article about Examining a URL Filtering profile provided by the UC Berkeley IT Service Hub - Knowledge Portal
The Information Security Office (ISO) provides security profiles that individual departments can use in their own firewall environments. To understand the settings and evaluate them for local use, administrators should review the profiles within the management console. The steps below outline how to examine URL Filtering profiles.
CRITICAL PRIVACY WARNING: The misuse of URL Filtering profiles may have significant privacy implications. If you are considering a custom profile that blocks or alerts on categories other than command-and-control, malware, phishing, threat-malicious_URLs, and ucbsec-URLs, you must consult with ISO and the Campus Privacy Office prior to implementation.
ucbsec-url_filter). Opening the profile displays the categories and the firewall's behavior for access attempts or credential submissions. By default, ISO blocks five high-risk categories:
ucbsec-URLs_threats: A custom list managed by ISO for sites specifically targeting campus users.| Option | Behavior |
|---|---|
| Alert | Generates a log entry but allows the traffic to pass. |
| Allow | Permits the traffic without logging. |
| Block | Prevents the traffic from reaching the destination. |
| Continue | Displays a warning page to the user but allows them to proceed by clicking a button. |
| Override | Displays a warning page requiring a system-wide password to proceed (rarely used on campus). |
| None | Only for custom categories; ignores the category in the filter but allows it to be used in other policies. |
The Overrides tab lists specific URLs that are explicitly allowed or blocked regardless of their category. This ensures critical services (e.g., Google/Gmail) remain accessible even if a category is restricted.
The URL Filtering Settings determine what information is logged and whether Safe Search is enforced. ISO configures logging to capture only the minimum information necessary for incident response. Safe Search Enforcement can be used to block search queries unless strict provider-side filters are enabled.
This feature detects if a user is submitting campus credentials to a potentially fraudulent site. Detection can be based on:
For technical documentation, visit the vendor site: URL Filtering Profile Documentation.