<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block on APP-ID (Apache Log4j ) in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/452810#M1415</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;After a bit of help ...I' have never created a block type rule on a Palo and now my boss wants me to create a .block rule for the above.&lt;/P&gt;&lt;P&gt;We have about 300 policies in the our firewall so no idea how to create a block and apply it .&lt;/P&gt;&lt;P&gt;Can anybody give me any pointers ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Dec 2021 12:37:36 GMT</pubDate>
    <dc:creator>Scott64</dc:creator>
    <dc:date>2021-12-13T12:37:36Z</dc:date>
    <item>
      <title>Block on APP-ID (Apache Log4j )</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/452810#M1415</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;After a bit of help ...I' have never created a block type rule on a Palo and now my boss wants me to create a .block rule for the above.&lt;/P&gt;&lt;P&gt;We have about 300 policies in the our firewall so no idea how to create a block and apply it .&lt;/P&gt;&lt;P&gt;Can anybody give me any pointers ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 12:37:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/452810#M1415</guid>
      <dc:creator>Scott64</dc:creator>
      <dc:date>2021-12-13T12:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Block on APP-ID (Apache Log4j )</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/453290#M1422</link>
      <description>&lt;P&gt;You need to do it by applying vulnerability security profile to each policy, or edit the security profiles you already applied to the security rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, the default action of log4j vulnerability signatures are "reset-server" and severity are critical:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sample_Wu_0-1639537778768.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38152i0F583561A4C8FCFC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sample_Wu_0-1639537778768.png" alt="Sample_Wu_0-1639537778768.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You just need to make sure the rule in each security profile is included severity critical and action is default or other suitable type, as below screenshot of the default profile:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sample_Wu_1-1639537997579.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38153i2C20A6A7FE4385A7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sample_Wu_1-1639537997579.png" alt="Sample_Wu_1-1639537997579.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just provide me thought for you as a reference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sample&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 03:14:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/453290#M1422</guid>
      <dc:creator>Sample_Wu</dc:creator>
      <dc:date>2021-12-15T03:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Block on APP-ID (Apache Log4j )</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/453347#M1423</link>
      <description>&lt;P&gt;Hi - Thanks for that&amp;nbsp; - I have created what I hope is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture0.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38158iD75BB4D1DBDC7BB7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Capture0.PNG" alt="Capture0.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38159i32BABFBEBC79DFAC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Capture1.png" alt="Capture1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 11:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/453347#M1423</guid>
      <dc:creator>Scott64</dc:creator>
      <dc:date>2021-12-15T11:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Block on APP-ID (Apache Log4j )</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/465822#M1500</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139060"&gt;@Scott64&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;After a bit of help ...I' have never created a block type rule on a Palo and now my boss wants me to create a .block rule for the above.&lt;/P&gt;&lt;P&gt;We have about 300 policies in the our firewall so no idea how to create a block and apply it .&lt;/P&gt;&lt;P&gt;Can anybody give me any pointers ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Upgrade to Log4j 2.3.2 (for Java 6), 2.12.4 (for Java 7), or 2.17.1 (for Java 8 and later).&lt;/P&gt;&lt;P&gt;In prior releases confirm that if the JDBC Appender is being used it is not configured to use any protocol other than Java.&lt;/P&gt;&lt;P&gt;Note that only the log4j-core JAR file is impacted by this vulnerability. Applications using only the log4j-api JAR file without the log4j-core JAR file are not impacted by this vulnerability.&lt;/P&gt;&lt;P&gt;Also note that Apache Log4j is the only Logging Services subproject affected by this vulnerability. Other projects like Log4net and Log4cxx are not impacted by this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 09:46:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-on-app-id-apache-log4j/m-p/465822#M1500</guid>
      <dc:creator>Kuhic567</dc:creator>
      <dc:date>2022-02-15T09:46:24Z</dc:date>
    </item>
  </channel>
</rss>

