<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security settings on NGFW to block dangerous user agent in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-settings-on-ngfw-to-block-dangerous-user-agent/m-p/583041#M2953</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/530444383"&gt;@E.SilvaHueck&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You could setup a custom vulnerability signature and set it up so it's blocked across your network. As an example, blocking GPTBot you could do the following assuming that you're decrypting inbound traffic.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;                                &amp;lt;pattern-match&amp;gt;
                                  &amp;lt;pattern&amp;gt;User-Agent:.+GPTBot/&amp;lt;/pattern&amp;gt;
                                  &amp;lt;context&amp;gt;http-req-headers&amp;lt;/context&amp;gt;
                                  &amp;lt;negate&amp;gt;no&amp;lt;/negate&amp;gt;
                                &amp;lt;/pattern-match&amp;gt;&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 09 Apr 2024 13:30:00 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2024-04-09T13:30:00Z</dc:date>
    <item>
      <title>Security settings on NGFW to block dangerous user agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-settings-on-ngfw-to-block-dangerous-user-agent/m-p/583009#M2952</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good morning!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to get guidance from you regarding how to block user agents on Paloalto NGFW. I mean, when I am managing Web Application Firewalls (WAF) from other provider. I am able to configure a section within the security section in the WAF, where I can block bad bots, and any other bad user agent (e.g. python, Go lang, Java, etc) used by not authorised external users to scan the website for vulnerabilities, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to setting up a similar security measure within Paloalto NGFW? If it is so. Could you help providing guidance for this security setting for me please?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;Elias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 07:14:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-settings-on-ngfw-to-block-dangerous-user-agent/m-p/583009#M2952</guid>
      <dc:creator>E.SilvaHueck</dc:creator>
      <dc:date>2024-04-09T07:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Security settings on NGFW to block dangerous user agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-settings-on-ngfw-to-block-dangerous-user-agent/m-p/583041#M2953</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/530444383"&gt;@E.SilvaHueck&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You could setup a custom vulnerability signature and set it up so it's blocked across your network. As an example, blocking GPTBot you could do the following assuming that you're decrypting inbound traffic.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;                                &amp;lt;pattern-match&amp;gt;
                                  &amp;lt;pattern&amp;gt;User-Agent:.+GPTBot/&amp;lt;/pattern&amp;gt;
                                  &amp;lt;context&amp;gt;http-req-headers&amp;lt;/context&amp;gt;
                                  &amp;lt;negate&amp;gt;no&amp;lt;/negate&amp;gt;
                                &amp;lt;/pattern-match&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 09 Apr 2024 13:30:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-settings-on-ngfw-to-block-dangerous-user-agent/m-p/583041#M2953</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-04-09T13:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security settings on NGFW to block dangerous user agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-settings-on-ngfw-to-block-dangerous-user-agent/m-p/583050#M2954</link>
      <description>&lt;P&gt;Thanks a lot for the information!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 14:35:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-settings-on-ngfw-to-block-dangerous-user-agent/m-p/583050#M2954</guid>
      <dc:creator>E.SilvaHueck</dc:creator>
      <dc:date>2024-04-09T14:35:56Z</dc:date>
    </item>
  </channel>
</rss>

