<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Malicious IP address log sudden increasein traffic in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/malicious-ip-address-log-sudden-increasein-traffic/m-p/574830#M2535</link>
    <description>&lt;P&gt;Our Malicious IP Traffic Alert typically registers a few dozen hits a day. However over the last weekend this has suddenly increased to a couple of thousand a day. I cannot see anything different apart from the quantity. The IP addresses are the same or from the same subnet.&amp;nbsp; Should I just leave it or what actions would you suggest.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2024 22:56:32 GMT</pubDate>
    <dc:creator>peeryog</dc:creator>
    <dc:date>2024-01-29T22:56:32Z</dc:date>
    <item>
      <title>Malicious IP address log sudden increasein traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/malicious-ip-address-log-sudden-increasein-traffic/m-p/574830#M2535</link>
      <description>&lt;P&gt;Our Malicious IP Traffic Alert typically registers a few dozen hits a day. However over the last weekend this has suddenly increased to a couple of thousand a day. I cannot see anything different apart from the quantity. The IP addresses are the same or from the same subnet.&amp;nbsp; Should I just leave it or what actions would you suggest.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 22:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/malicious-ip-address-log-sudden-increasein-traffic/m-p/574830#M2535</guid>
      <dc:creator>peeryog</dc:creator>
      <dc:date>2024-01-29T22:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Malicious IP address log sudden increasein traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/malicious-ip-address-log-sudden-increasein-traffic/m-p/574903#M2538</link>
      <description>&lt;P&gt;Are you seeing these hits in a security policy. Probably using the PAN "malicious IPs"&amp;nbsp; dynamic address group?&amp;nbsp; Have you tried configuring a "Zone Protection Profile".&amp;nbsp; The default action is alert but you can configure it to drop or even drop for X minutes. If you are being scanned there is not much you can do other than drop the packets. If this was my network I would look at threat logs and try to determine what resource they are attacking. You probably have something exposed that has a vulnerability.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 10:31:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/malicious-ip-address-log-sudden-increasein-traffic/m-p/574903#M2538</guid>
      <dc:creator>SteveKrall</dc:creator>
      <dc:date>2024-01-30T10:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Malicious IP address log sudden increasein traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/malicious-ip-address-log-sudden-increasein-traffic/m-p/574931#M2539</link>
      <description>&lt;P&gt;Yes they are set up to be dropped and that is working. It has always worked, its just that there has been a sudden and dramatic increase in these types of alerts so I am wondering if there is something else I should be alert to , as you mentioned, something exposed that has piqued some external interest.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 14:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/malicious-ip-address-log-sudden-increasein-traffic/m-p/574931#M2539</guid>
      <dc:creator>peeryog</dc:creator>
      <dc:date>2024-01-30T14:20:33Z</dc:date>
    </item>
  </channel>
</rss>

