Palo Alto

Blocking Youtube Using Palo Alto URL Category

The Bandwidth Killer
to be honest i learn a lot from youtube whether cisco configuration or paloalto or even other things
but during work hour many user using youtube to hear songs, watch a movie trailer which kill the internet bandwidth so i explain earlier how to block facebook using APP-ID
but Youtube APP-ID is little diffrent cause it depend in google-base which will forbid google website too
so URL Category may save the Day
this remind me of Microsoft TMG

So first let create a URL Category
Go to Objects – Custom objects – URL Category – add new
Add URL ( Also you can add more (*
now we create a security policy
Go to Policies – Security – add new (Stop Youtube)
Select the Source Zone (inside) and the Source Address (My Laptop IP  Address)
Select the user aysar.mohamed (Me)4
Select the Destination as my Outside Interface5
Select any in Application tab6
well here we go
in Service/URL Category we select the (Youtube) Category that we create earlier7
put the Action to deny8
now when i try to open Youtube i got the deny messgae ;D9
As you can see from the log i got the (Reset-both ) Action in rule of Stop youtube 10a




6 thoughts on “Blocking Youtube Using Palo Alto URL Category

  1. Palo guy says:

    This is ugly solution because user does not get notification just 404.
    Create URL profile where action for this custom category is block.
    Change action in your current policy to “allow”.
    Leave URL category in place and add URL blocking profile that you just created.
    In this case this policy only applies if user goes to youtube url, traffic gets to HTTP GET and block page is shown to user.

    Also you might want to block application quic because Chrome uses quic to communicate with Google services.
    There are other things to get better results like also utilizing app-id and applying decryption but this is good for a start.

    And if HR does not permit to block youtube then QoS to 100Kbit 🙂


    • Hello Maha
      i actually implemnt the same solution in over 5 sites and its working perfectly
      may i ask did you also add the other option

      also in monitoring tab which policy are you matching
      if i can understand the full scenario i may solve it


  2. Maha says:

    Hi there,
    I added those as well but still no luck.
    the rule that my traffic is hitting is another one down in the list. I made the block_youtube rule #1.


    • Hi Mah
      in my Previous Article of blocking facebook i add decryption policy so it might cause your traffic is an SSL that why your palo alto cant read it if he cant decrypt it
      so try to use the same method and i will also check from my side


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s