<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to get container defender to detect denied IP address on host in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/521616#M808</link>
    <description>&lt;P&gt;Hi JensWegar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, they are very similar. The key difference is&amp;nbsp;&lt;SPAN&gt;host protection is more geared towards the system services/apps that reside on the hosts - typically they need to be systemd services&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Nov 2022 00:59:58 GMT</pubDate>
    <dc:creator>USheikh</dc:creator>
    <dc:date>2022-11-18T00:59:58Z</dc:date>
    <item>
      <title>Unable to get container defender to detect denied IP address on host</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/520312#M785</link>
      <description>&lt;P&gt;For some reason I am unable to see any events being generated for denied IP addresses when running a container defender on one of our hosts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;installed a container defender on a linux host.&lt;/LI&gt;
&lt;LI&gt;created a host policy that targets the host where the container defender runs.&lt;/LI&gt;
&lt;LI&gt;Added google dns (8.8.8.8) to list of denied IP addresses in the host policy.&lt;/LI&gt;
&lt;LI&gt;Tried to run ping/curl against that IP address.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Based on the above I expected to see host audit events alerting me to the denied IP address under Admin-&amp;gt;Compute-&amp;gt;Monitor-&amp;gt;Events. But there is no activity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I do the exact same steps, but instead of adding an IP i add a port (e.g. 80,443) to the denied ports list, then I start to see activity in Monitor-&amp;gt;Events immediately. So looks like the defender is able to detect some things from the host, but not IP connectivity for some reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anybody have an idea of what is going on? And perhaps how to debug the issue? Or is there something fundamental I don't understand with host protection and container defenders.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But for some reason I don't see any events/alerts being generated when I try to ping or curl an IP that&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 12:39:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/520312#M785</guid>
      <dc:creator>JensWegar</dc:creator>
      <dc:date>2022-11-04T12:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get container defender to detect denied IP address on host</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/521489#M804</link>
      <description>&lt;P&gt;Hi JensWegar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To block dns at the host level, please install host defender on your linux host, and create a host policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the documentation of runtime defense for hosts:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/runtime_defense/runtime_defense_hosts" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/runtime_defense/runtime_defense_hosts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And to install host defender please refer to the following documentation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/install/install_defender/install_host_defender" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/install/install_defender/install_host_defender&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 23:52:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/521489#M804</guid>
      <dc:creator>USheikh</dc:creator>
      <dc:date>2022-11-16T23:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get container defender to detect denied IP address on host</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/521520#M806</link>
      <description>&lt;P&gt;Thanks for your reply, USheikh. My understanding of the container defender vs host defender is that the container defender does everything that the host defender does, so if a host runs the docker daemon then one should install a container defender (&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/install/defender_types" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/install/defender_types&lt;/A&gt;). But based on your answer, do I have to install both a container defender AND host defender to get full protection on the host?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 08:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/521520#M806</guid>
      <dc:creator>JensWegar</dc:creator>
      <dc:date>2022-11-17T08:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get container defender to detect denied IP address on host</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/521616#M808</link>
      <description>&lt;P&gt;Hi JensWegar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, they are very similar. The key difference is&amp;nbsp;&lt;SPAN&gt;host protection is more geared towards the system services/apps that reside on the hosts - typically they need to be systemd services&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 00:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unable-to-get-container-defender-to-detect-denied-ip-address-on/m-p/521616#M808</guid>
      <dc:creator>USheikh</dc:creator>
      <dc:date>2022-11-18T00:59:58Z</dc:date>
    </item>
  </channel>
</rss>

