{"id":1211,"date":"2026-09-13T19:04:12","date_gmt":"2026-09-13T19:04:12","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1211"},"modified":"2026-09-13T19:04:12","modified_gmt":"2026-09-13T19:04:12","slug":"url-filtering","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/url-filtering\/","title":{"rendered":"URL Filtering"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: URL FILTERING\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">URL filtering reads the full web address, not just the domain. Doing that on encrypted traffic means decrypting it, and that single requirement decides whether the control is worth deploying.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Network<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>URL filtering inspects the complete web address a user requests and decides whether to allow it, block it, warn the user or simply log it. Because it sees the path rather than only the domain, it can permit one part of a site and refuse another. Nearly all web traffic is encrypted, so this depth of visibility depends on inspecting inside TLS.<\/p>\n<\/div>\n\n<p>Deployed without that inspection, URL filtering quietly degrades into something you already have.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#sees\">What URL filtering sees<\/a><\/li>\n    <li><a href=\"#actions\">The five enforcement actions<\/a><\/li>\n    <li><a href=\"#decrypt\">The decryption problem<\/a><\/li>\n    <li><a href=\"#versus\">URL, DNS and web filtering<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"sees\">What URL filtering sees<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 186\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"A web address split into the domain portion visible to DNS filtering and the path portion visible only to URL filtering.\">\n  <rect x=\"14\" y=\"22\" width=\"298\" height=\"72\" rx=\"13\" fill=\"#e2eff7\"\/>\n  <text x=\"163\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Domain<\/text>\n  <text x=\"163\" y=\"70\" text-anchor=\"middle\" font-family=\"'DM Mono',monospace\" font-size=\"12\" fill=\"#0f1538\">files.example.com<\/text>\n  <text x=\"163\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#2f6f96\">Visible to DNS filtering<\/text>\n\n  <rect x=\"320\" y=\"22\" width=\"426\" height=\"72\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"533\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Path, parameters and file<\/text>\n  <text x=\"533\" y=\"70\" text-anchor=\"middle\" font-family=\"'DM Mono',monospace\" font-size=\"12\" fill=\"#0f1538\">\/public\/share\/upload?id=44&amp;f=payroll.xlsx<\/text>\n  <text x=\"533\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#1c267a\">Visible only after decryption<\/text>\n\n  <rect x=\"14\" y=\"110\" width=\"732\" height=\"60\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"132\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">One domain can host both a service you rely on and a path you must not allow.<\/text>\n  <text x=\"380\" y=\"151\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">Blocking at the domain is all or nothing. The path is where the actual policy decision lives.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Input<\/th><th>What the decision uses<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Category<\/td><td>A classification of the site or page, such as file sharing, webmail, social or gambling<\/td><\/tr>\n    <tr><td>Reputation<\/td><td>A risk score based on age, hosting history and observed behaviour, which catches sites too new to be categorised<\/td><\/tr>\n    <tr><td>Path<\/td><td>The specific page or endpoint, which is what allows one section of a site to be treated differently from another<\/td><\/tr>\n    <tr><td>File type<\/td><td>The extension being requested, so executables can be refused while documents are permitted<\/td><\/tr>\n    <tr><td>User or group<\/td><td>The same address treated differently depending on who is asking, tied to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">identity<\/a><\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"actions\" class=\"c-sage\">The five enforcement actions<\/h2>\n\n<p>Unlike a name lookup, which either resolves or does not, a web request can be handled in several ways.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Action<\/th><th>When to use it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Allow<\/td><td>Permitted, with the request logged for later review<\/td><\/tr>\n    <tr><td>Block<\/td><td>Refused outright, with a page explaining why. Reserved for genuine risk and clear policy breaches<\/td><\/tr>\n    <tr><td>Warn and continue<\/td><td>An interstitial page the user can click past. Records that they were told, which changes behaviour without generating support tickets<\/td><\/tr>\n    <tr><td>Log only<\/td><td>No enforcement, full visibility. The correct first phase of any rollout<\/td><\/tr>\n    <tr><td>Quota<\/td><td>Time or bandwidth limits on a category rather than an outright ban<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Start in log only, then warn, then block<\/p>\n  <p>Blocking on day one produces a queue of exception requests and a security team that becomes the reason people cannot do their jobs. Running in log-only mode for a few weeks shows what staff genuinely use, which categories are noise and which single sites need permitting before enforcement begins. Warn-and-continue then handles most acceptable-use cases on its own, because very few people click through a warning page to reach something they should not.<\/p>\n<\/div>\n\n<h2 id=\"decrypt\" class=\"c-plum\">The decryption problem<\/h2>\n\n<p>Encrypted traffic hides the path. To read it, the filter terminates the connection, inspects, and re-encrypts, which requires its own certificate authority to be trusted on every device.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Cost<\/th><th>What it means in practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Certificate deployment<\/td><td>A root certificate installed and maintained on every managed device. Unmanaged and personal devices cannot be covered<\/td><\/tr>\n    <tr><td>Certificate pinning<\/td><td>Many applications refuse a substituted certificate by design and simply stop working, producing a permanent exclusion list<\/td><\/tr>\n    <tr><td>Privacy and legal exposure<\/td><td>Banking, health and personal accounts are typically excluded, both for law and for staff trust<\/td><\/tr>\n    <tr><td>Performance<\/td><td>Every session is terminated and rebuilt, which adds latency and requires capacity<\/td><\/tr>\n    <tr><td>The exclusion list<\/td><td>Each exception becomes a channel nobody inspects, and attackers are aware of which categories are conventionally excluded<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Without decryption, URL filtering is domain filtering<\/p>\n  <p>An undecrypted filter can read only the hostname exchanged during connection setup. It cannot see the path, cannot distinguish one page from another on the same site, and cannot inspect a file being downloaded. That is precisely the visibility <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a> already gives you, at far lower cost and with no certificate estate to maintain. Deploying URL filtering without a decryption decision is paying proxy prices for domain-level results.<\/p>\n<\/div>\n\n<h2 id=\"versus\" class=\"c-sky\">URL, DNS and web filtering<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Property<\/th><th>URL filtering<\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a><\/th><th>Secure web gateway<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Sees<\/td><td>The full path and file requested<\/td><td>The domain only<\/td><td>Path plus the content of the response<\/td><\/tr>\n    <tr><td>Acts<\/td><td>During the request<\/td><td>Before any connection<\/td><td>Throughout the session<\/td><\/tr>\n    <tr><td>Needs decryption<\/td><td>Yes, for real depth<\/td><td>No<\/td><td>Yes<\/td><\/tr>\n    <tr><td>Covers non-web traffic<\/td><td>No<\/td><td>Yes, anything resolving a name<\/td><td>No<\/td><\/tr>\n    <tr><td>Enforcement options<\/td><td>Allow, block, warn, log, quota<\/td><td>Resolve or refuse<\/td><td>Full policy including content actions<\/td><\/tr>\n    <tr><td>Cost and complexity<\/td><td>Moderate<\/td><td>Low<\/td><td>High<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Content filtering is the umbrella term for all three. A secure web gateway is effectively URL filtering plus malware inspection of the response body, and in a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sase\/\">SASE<\/a> architecture that gateway is the delivery vehicle for both.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto is not a full proxy gateway. There is no break-and-inspect deployment and no certificate authority to roll out across your fleet, which is a deliberate choice rather than a gap: for a team of thirty, the maintenance and exclusion list of a decrypting proxy usually costs more than it returns.<\/p>\n\n<p>Content filtering runs in the endpoint module, so category and reputation policy travels with the laptop instead of applying only inside an office network. Around it, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a> catches anything that resolves a name including non-browser traffic, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">endpoint protection<\/a> handles what a downloaded file does once it lands, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/device-control\/\">device control<\/a> governs where data can be copied, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">data loss prevention<\/a> covers what leaves.<\/p>\n\n<p>That combination reaches most of what a web filtering policy is actually bought to achieve, without the decryption estate. Events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">one SIEM<\/a>, and the resulting records support the acceptable-use and malicious-code controls sampled under <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa\/\">HIPAA<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Web policy without a proxy to run<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Content and DNS filtering enforced on the device, with endpoint protection, device control and data loss prevention behind them. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is URL filtering?<\/summary>\n  <p>A control that inspects the full web address requested and applies policy to it, allowing, blocking, warning or logging based on category, reputation, path, file type and who is asking. Seeing the path is what separates it from domain-level filtering.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between URL filtering and DNS filtering?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a> sees the domain and acts before any connection, covering all protocols at low cost. URL filtering sees the full path during the request and can treat two pages on the same site differently, but needs decryption to do so.<\/p>\n<\/details>\n\n<details>\n  <summary>Does URL filtering require TLS inspection?<\/summary>\n  <p>For anything beyond the hostname, yes. Without it the filter reads only the domain from connection setup, which is the same visibility DNS filtering provides far more cheaply.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between URL filtering and a secure web gateway?<\/summary>\n  <p>A gateway is the broader product. It performs URL filtering and adds malware inspection of the response, data loss controls and often cloud application policy. URL filtering is one function inside it.<\/p>\n<\/details>\n\n<details>\n  <summary>Should you block or warn?<\/summary>\n  <p>Warn for acceptable-use categories and block for genuine risk. Start in log-only mode to learn what staff actually use, then move to warnings. Very few people click through a warning page to reach something they know they should not.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS Filtering<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">EPP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/device-control\/\">Device Control<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">DLP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sase\/\">SASE<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>URL filtering reads the full web address, not just the domain. Doing that on encrypted traffic means decrypting it, and\u2026<\/p>\n","protected":false},"author":8,"featured_media":1212,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[614,612,613],"class_list":["post-1211","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-tls-inspection","tag-url-filtering","tag-url-filtering-vs-dns-filtering"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1211"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1211\/revisions"}],"predecessor-version":[{"id":1213,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1211\/revisions\/1213"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1212"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1211"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}