<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP blocked then allowed in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574767#M2533</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Glad you found what you needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2024 17:41:20 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2024-01-29T17:41:20Z</dc:date>
    <item>
      <title>IP blocked then allowed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/573581#M2474</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;I'm reviewing a logs regarding a low reputation IP which in the first log it's action is dropped, and 5 minutes later 3 logs with action allowed. Why does it dropped then allowed it?&lt;BR /&gt;&lt;BR /&gt;Logs&lt;/P&gt;
&lt;P&gt;category: spyware&lt;/P&gt;
&lt;P&gt;action: dropped&lt;/P&gt;
&lt;P&gt;Threat Name: CobaltStrike.Gen Command and Control Traffic&lt;BR /&gt;Threat ID: 18005&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 03:45:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/573581#M2474</guid>
      <dc:creator>ridzuan.a</dc:creator>
      <dc:date>2024-01-19T03:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: IP blocked then allowed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/573583#M2475</link>
      <description>&lt;P&gt;I'm new to the forum, thanks in advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 03:46:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/573583#M2475</guid>
      <dc:creator>ridzuan.a</dc:creator>
      <dc:date>2024-01-19T03:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: IP blocked then allowed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/573990#M2499</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Not sure if its the case here however logs are typically written at 'session end'. We would need to see redacted logs to try and figure this out. Just black out the source and destination IP's along with anything that could identify your company etc.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 21:19:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/573990#M2499</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-01-22T21:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: IP blocked then allowed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574052#M2501</link>
      <description>&lt;P&gt;Hi, please find the ss below&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FW logs blocked then allow.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56778i13E120F36D46D49B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="FW logs blocked then allow.jpg" alt="FW logs blocked then allow.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 08:35:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574052#M2501</guid>
      <dc:creator>ridzuan.a</dc:creator>
      <dc:date>2024-01-23T08:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: IP blocked then allowed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574099#M2507</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;So the 'later' traffic is UDP (DNS-Base) so it has to 'time out' since there is no fin packets. This is the most likely reason for the later timestamp in the logs. The policy is most likely set to log at session end, which is best practice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 15:43:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574099#M2507</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-01-23T15:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: IP blocked then allowed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574236#M2512</link>
      <description>&lt;P&gt;does UDP has fin packets?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 06:42:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574236#M2512</guid>
      <dc:creator>ridzuan.a</dc:creator>
      <dc:date>2024-01-24T06:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: IP blocked then allowed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574237#M2513</link>
      <description>&lt;P&gt;i did a bit of research from your explanation, using the first link below to understand the session end. then using data from Session End reason: threat, i found out the answer in the second link. thanks for your help&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 06:45:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574237#M2513</guid>
      <dc:creator>ridzuan.a</dc:creator>
      <dc:date>2024-01-24T06:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: IP blocked then allowed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574767#M2533</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Glad you found what you needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 17:41:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ip-blocked-then-allowed/m-p/574767#M2533</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-01-29T17:41:20Z</dc:date>
    </item>
  </channel>
</rss>

