Examining a URL Filtering profile

A knowledge base article about Examining a URL Filtering profile provided by the UC Berkeley IT Service Hub - Knowledge Portal

Overview

The Information Security Office (ISO) provides security profiles that individual departments can use in their own firewall environments. To understand the settings and evaluate them for local use, administrators should review the profiles within the management console. The steps below outline how to examine URL Filtering profiles.

CRITICAL PRIVACY WARNING: The misuse of URL Filtering profiles may have significant privacy implications. If you are considering a custom profile that blocks or alerts on categories other than command-and-control, malware, phishing, threat-malicious_URLs, and ucbsec-URLs, you must consult with ISO and the Campus Privacy Office prior to implementation.

How to Examine URL Filtering Profiles

  1. Log into https://panorama.net.berkeley.edu using single sign-on.
  2. Select the Objects tab from the top navigation bar.
  3. Under the Security Profiles menu in the left pane, select URL Filtering.
    Panorama sidebar menu showing URL Filtering selected under Security Profiles.
  4. Select the profile you wish to examine (e.g., ucbsec-url_filter). Opening the profile displays the categories and the firewall's behavior for access attempts or credential submissions.
    Main URL Filtering window showing a list of categories and their associated actions.

Blocked Categories

By default, ISO blocks five high-risk categories:

Configuration Action Options

Option Behavior
Alert Generates a log entry but allows the traffic to pass.
Allow Permits the traffic without logging.
Block Prevents the traffic from reaching the destination.
Continue Displays a warning page to the user but allows them to proceed by clicking a button.
Override Displays a warning page requiring a system-wide password to proceed (rarely used on campus).
None Only for custom categories; ignores the category in the filter but allows it to be used in other policies.

Overrides and Allow Lists

The Overrides tab lists specific URLs that are explicitly allowed or blocked regardless of their category. This ensures critical services (e.g., Google/Gmail) remain accessible even if a category is restricted.

Overrides tab showing Gmail and Google URLs in the Allow List.

Logging and Safe Search

The URL Filtering Settings determine what information is logged and whether Safe Search is enforced. ISO configures logging to capture only the minimum information necessary for incident response. Safe Search Enforcement can be used to block search queries unless strict provider-side filters are enabled.

URL Filtering settings tab showing logging and Safe Search options.

User Credential Detection

This feature detects if a user is submitting campus credentials to a potentially fraudulent site. Detection can be based on:

User Credential Detection tab showing configuration for Domain Credentials.


Additional Resources

For technical documentation, visit the vendor site: URL Filtering Profile Documentation.