<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot change action for special Threat ID in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574267#M2515</link>
    <description>&lt;P&gt;On our 5410 with PANOS 10.2.7-h3 installed I can see a lot of threats with ID 89953 (Inline Cloud Analyzed Unknown-TCP Command and Control Traffic Detection), severity = high, default action = alert.&lt;/P&gt;
&lt;P&gt;I want to change the default action via Anti-Spyware-Profile &amp;gt; Inline Cloud Analysis, but it's not possible for this special threat.&lt;/P&gt;
&lt;P&gt;Any idea how to change this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thx in advance&lt;/P&gt;
&lt;P&gt;Thomas&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jan 2024 10:52:55 GMT</pubDate>
    <dc:creator>tugips</dc:creator>
    <dc:date>2024-01-24T10:52:55Z</dc:date>
    <item>
      <title>Cannot change action for special Threat ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574267#M2515</link>
      <description>&lt;P&gt;On our 5410 with PANOS 10.2.7-h3 installed I can see a lot of threats with ID 89953 (Inline Cloud Analyzed Unknown-TCP Command and Control Traffic Detection), severity = high, default action = alert.&lt;/P&gt;
&lt;P&gt;I want to change the default action via Anti-Spyware-Profile &amp;gt; Inline Cloud Analysis, but it's not possible for this special threat.&lt;/P&gt;
&lt;P&gt;Any idea how to change this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thx in advance&lt;/P&gt;
&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 10:52:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574267#M2515</guid>
      <dc:creator>tugips</dc:creator>
      <dc:date>2024-01-24T10:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot change action for special Threat ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574355#M2517</link>
      <description>&lt;P&gt;You arent able to change the predefined security profiles if youre trying to change it from there. You would have to clone the profile and edit it there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The threat ID is for this entirely, if you wanted to disable this you could set the action to alert. However, down below if where you can set specific exceptions for the threat.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Claw4609_0-1706128459203.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56848i72139C9D74CDE570/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Claw4609_0-1706128459203.png" alt="Claw4609_0-1706128459203.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 20:35:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574355#M2517</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-01-24T20:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot change action for special Threat ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574414#M2519</link>
      <description>&lt;P&gt;Sure, I've always been using a custom profile and all actions within "Inline Cloud Analysis" are set to "reset-both".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cloud analysis.JPG" style="width: 981px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56857i491638B03850D6FA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Cloud analysis.JPG" alt="Cloud analysis.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I've found out in the meantime:&lt;/P&gt;
&lt;P&gt;In some rare cases threat IDs within the range 89950-89953 are blocked.&lt;/P&gt;
&lt;P&gt;No idea why...&lt;/P&gt;
&lt;P&gt;And I still want to block &lt;STRONG&gt;all&lt;/STRONG&gt; those threats.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Threat-8995x.JPG" style="width: 804px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56858i1955DCBC239BDED4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Threat-8995x.JPG" alt="Threat-8995x.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 07:29:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574414#M2519</guid>
      <dc:creator>tugips</dc:creator>
      <dc:date>2024-01-25T07:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot change action for special Threat ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574478#M2521</link>
      <description>&lt;P&gt;Just to clarify, are you wanting to block or allow threat IDs&amp;nbsp;89950-89953? While I dont have much of this traffic being flagged in my environment, its possible that this operates similar to Wildfire, and it initially alerts/allows the traffic before the cloud comes back and says no for future connections.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 14:22:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-change-action-for-special-threat-id/m-p/574478#M2521</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-01-25T14:22:45Z</dc:date>
    </item>
  </channel>
</rss>

