<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About vulnerability protection and url filter action in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380690#M1020</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Thank you very much. For the logs you send, if you set the vulnerability defense profile to drop severity critical Will action be drop?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 01:29:28 GMT</pubDate>
    <dc:creator>t-katsuki</dc:creator>
    <dc:date>2021-01-19T01:29:28Z</dc:date>
    <item>
      <title>About vulnerability protection and url filter action</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380444#M1016</link>
      <description>&lt;PRE&gt;&lt;SPAN&gt;I set medium to drop in the vulnerability protection profile, &lt;BR /&gt;but when I check the log, Severity is medium, but action is alert. Why not drop? &lt;BR /&gt;If you check the verbose log, the type is url and action is alert. Severity is informational. &lt;BR /&gt;In this case, isn't url processing prioritized and not dropped?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 18 Jan 2021 09:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380444#M1016</guid>
      <dc:creator>t-katsuki</dc:creator>
      <dc:date>2021-01-18T09:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: About vulnerability protection and url filter action</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380458#M1017</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148179"&gt;@t-katsuki&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First where are you looking for the logs, i mean under Threat or URL filtering section? If you want to see vulnerability protection profile related logs, please check under threat logs tab. Also before checking logs under said tab, you need to have that profile to be mapped to the security policy which is allowing the traffic. Unless you have VP profile attached to the security policy, it wont come into picture while processing the traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 09:40:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380458#M1017</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-01-18T09:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: About vulnerability protection and url filter action</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380460#M1018</link>
      <description>&lt;P&gt;there is a distinct diffeentce between vulnerability logs and url logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;an url log will &lt;EM&gt;always&lt;/EM&gt; be severity informational, the action will depend on what the category action is set to, so might be alert (url allowed), block-ur, continue, ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as you can see in the example below, there are 3 logs ssociated to a single session and all have a different severity and action&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the traffic log in green is a simple allow rule, no severity. this is because the session was allowed intitially by the security policy&lt;/P&gt;&lt;P&gt;the url filtering log in red is informational and alert, because url logs are always informational, and the url category was allowed in the url filtering profile&lt;/P&gt;&lt;P&gt;the vulnerability profile in purple is critical and reset-both, because a vulnerability was found once the http connection started going and payload was transferred that contained something bad&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-01-18_10-46-42.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29575i32A061A586320FBA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2021-01-18_10-46-42.jpg" alt="2021-01-18_10-46-42.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 09:51:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380460#M1018</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-18T09:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: About vulnerability protection and url filter action</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380689#M1019</link>
      <description>&lt;P&gt;ありがとうございます。&lt;/P&gt;&lt;P&gt;セキュリティポリシーにセキュリティプロファイルが適用されているかどうかの確認は最も必要な点だと思います。脅威ログから該当の通信がセキュリティポリシーにヒットし、そのセキュリティポリシーにmedium drop の脆弱性防御カスタムプロファイルが適用されていることを確認できました。&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 01:21:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380689#M1019</guid>
      <dc:creator>t-katsuki</dc:creator>
      <dc:date>2021-01-19T01:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: About vulnerability protection and url filter action</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380690#M1020</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you very much. For the logs you send, if you set the vulnerability defense profile to drop severity critical Will action be drop?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 01:29:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/about-vulnerability-protection-and-url-filter-action/m-p/380690#M1020</guid>
      <dc:creator>t-katsuki</dc:creator>
      <dc:date>2021-01-19T01:29:28Z</dc:date>
    </item>
  </channel>
</rss>

