<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strange TCP traffic from PAN Firewall management IP going to Japan in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/strange-tcp-traffic-from-pan-firewall-management-ip-going-to/m-p/197230#M182</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I've noticed an strange event in our network. We have PAN 5020 and other PAN firewalls. The issue is from the management IP from one of them there is TCP traffic going to a Japanese server on port 135 (MSRPC). One of our Sensors detects it as "possible infection". Some vendors have suggested it is nothing and may be related to this since we have user agent ID enabled: &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Unexpected-Traffic-Seen-from-the-User-ID-Agent/ta-p/62830" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Unexpected-Traffic-Seen-from-the-User-ID-Agent/ta-p/62830&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But I'm not sure. Will this event warrant further exploring?&lt;/P&gt;</description>
    <pubDate>Sat, 27 Jan 2018 14:13:06 GMT</pubDate>
    <dc:creator>FR33BSD4LIFE</dc:creator>
    <dc:date>2018-01-27T14:13:06Z</dc:date>
    <item>
      <title>Strange TCP traffic from PAN Firewall management IP going to Japan</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/strange-tcp-traffic-from-pan-firewall-management-ip-going-to/m-p/197230#M182</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I've noticed an strange event in our network. We have PAN 5020 and other PAN firewalls. The issue is from the management IP from one of them there is TCP traffic going to a Japanese server on port 135 (MSRPC). One of our Sensors detects it as "possible infection". Some vendors have suggested it is nothing and may be related to this since we have user agent ID enabled: &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Unexpected-Traffic-Seen-from-the-User-ID-Agent/ta-p/62830" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Unexpected-Traffic-Seen-from-the-User-ID-Agent/ta-p/62830&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But I'm not sure. Will this event warrant further exploring?&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2018 14:13:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/strange-tcp-traffic-from-pan-firewall-management-ip-going-to/m-p/197230#M182</guid>
      <dc:creator>FR33BSD4LIFE</dc:creator>
      <dc:date>2018-01-27T14:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Strange TCP traffic from PAN Firewall management IP going to Japan</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/strange-tcp-traffic-from-pan-firewall-management-ip-going-to/m-p/197426#M183</link>
      <description>&lt;P&gt;Just to err on the side of caution I recommend opening a case with our support team and uploading a tech support file from the device that is generating this behavior.&amp;nbsp; Also, any log data relevant to this traffic would be helpful as well (traffic logs, etc. if available).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 15:58:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/strange-tcp-traffic-from-pan-firewall-management-ip-going-to/m-p/197426#M183</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-01-29T15:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Strange TCP traffic from PAN Firewall management IP going to Japan</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/strange-tcp-traffic-from-pan-firewall-management-ip-going-to/m-p/197454#M184</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would highly recommend you disable the user-id lookup on any untrusted/internet based zones. This can cause that type of traffic and leave the password for others to 'guess'. I would also recommend changing the user-id lookup password you use for wmi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 17:54:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/strange-tcp-traffic-from-pan-firewall-management-ip-going-to/m-p/197454#M184</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-29T17:54:10Z</dc:date>
    </item>
  </channel>
</rss>

