<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Spyware threat alerts in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578969#M2748</link>
    <description>&lt;P&gt;I would like to validate if the below monitored traffic on our internal firewall is service-affecting.&amp;nbsp; How can we address this dropped traffic?&lt;/P&gt;
&lt;P&gt;How can we cleanup these alerts?&amp;nbsp;&amp;nbsp;The same alert is shown on another FW 3430.&amp;nbsp; Is it a normal behavior of firewall management IP to send DNS query?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 06:34:21 GMT</pubDate>
    <dc:creator>Ryan_Volante</dc:creator>
    <dc:date>2024-03-01T06:34:21Z</dc:date>
    <item>
      <title>Spyware threat alerts</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578969#M2748</link>
      <description>&lt;P&gt;I would like to validate if the below monitored traffic on our internal firewall is service-affecting.&amp;nbsp; How can we address this dropped traffic?&lt;/P&gt;
&lt;P&gt;How can we cleanup these alerts?&amp;nbsp;&amp;nbsp;The same alert is shown on another FW 3430.&amp;nbsp; Is it a normal behavior of firewall management IP to send DNS query?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 06:34:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578969#M2748</guid>
      <dc:creator>Ryan_Volante</dc:creator>
      <dc:date>2024-03-01T06:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware threat alerts</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578972#M2749</link>
      <description>&lt;P&gt;You can configure DNS Sink holing to find out which actual IP Address generating this Spyware traffic, Based on that you can scan your device.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use the below document to configure DNS Sink holing.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGECA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGECA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 06:50:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578972#M2749</guid>
      <dc:creator>suba_muthuram</dc:creator>
      <dc:date>2024-03-01T06:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware threat alerts</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578975#M2750</link>
      <description>&lt;P&gt;Once we get to identify the IP address generating this spyware traffic, what will be the best approach to do next? And does it mean that this IP address is infected by a virus(spyware) or something?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 07:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578975#M2750</guid>
      <dc:creator>Ryan_Volante</dc:creator>
      <dc:date>2024-03-01T07:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware threat alerts</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578999#M2751</link>
      <description>&lt;P&gt;yes, There could be a possibility, the best approach is scan the host with an Antivirus software and verify is there any specific application has infected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/spyware-threat-alerts/m-p/578999#M2751</guid>
      <dc:creator>suba_muthuram</dc:creator>
      <dc:date>2024-03-01T10:43:42Z</dc:date>
    </item>
  </channel>
</rss>

