<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need confirmation from Palo alto on DNS Trojan ShadowPad Detected in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/need-confirmation-from-palo-alto-on-dns-trojan-shadowpad/m-p/548244#M1954</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244332"&gt;@Purushotham&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;If you have support account you can access &lt;SPAN data-reactid=".0.0.1.3"&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt; where you can search available PAN signatures/protections. If you search for "ShadowPad" - &lt;A href="https://threatvault.paloaltonetworks.com/?query=ShadowPad&amp;amp;type=" target="_blank"&gt;https://threatvault.paloaltonetworks.com/?query=ShadowPad&amp;amp;type=&lt;/A&gt; only AV signatures are available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you provide more details on the alert your customer have received?&lt;/P&gt;
&lt;P&gt;- What device has triggered this alert?&lt;/P&gt;
&lt;P&gt;- What this alert is detecting? What traffic has triggered this alert?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. TLS Version 1.1 Protocol Deprecated - Need to Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It is not very clear what you are trying to do, but I would assume you want to restrict TLS 1.1 traffic over PAN firewall. If that is a case you need to define SSL decryption profile - &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-concepts/ssl-protocol-settings-decryption-profile" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-concepts/ssl-protocol-settings-decryption-profile&lt;/A&gt; As you can see you can only do this only for decrypted traffic.&lt;/P&gt;
&lt;P&gt;1. Create SSL decryption profile&lt;/P&gt;
&lt;P&gt;2. Configure SSL protocol settings to match your requirements - min=TLS 1.2 and max=max (this will tell the FW to use the latest which it could support at the moment is 1.3, if in the future OS is updated to support higher it will automatically apply that)&lt;/P&gt;
&lt;P&gt;3. Create SSL decryption rule matching the traffic for which you want to enforce TLS1.2/1.3 and set action to decrypt, selecting the profile you created earlier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3.IP Forwarding Enabled - Need to disable IP forwarding.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This questions is not clear at all. It looks like finding from vulnerability scan or PenTest from endpoint. In order to assist you we will need little bit more clarification and background info.&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2023 13:12:07 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-07-05T13:12:07Z</dc:date>
    <item>
      <title>Need confirmation from Palo alto on DNS Trojan ShadowPad Detected</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/need-confirmation-from-palo-alto-on-dns-trojan-shadowpad/m-p/546973#M1946</link>
      <description>&lt;P&gt;1. Customer has encountered the new threat alert named&amp;nbsp;DNS Trojan ShadowPad Detected in their network but the traffic is passing through Palo alto firewall and it is allowed and no threat alerts are triggered in Palo Alto Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;TLS Version 1.1 Protocol Deprecated -&amp;nbsp;Need to Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.&lt;/P&gt;
&lt;P&gt;3.IP Forwarding Enabled -&amp;nbsp;Need to disable IP forwarding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please suggest on this.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 08:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/need-confirmation-from-palo-alto-on-dns-trojan-shadowpad/m-p/546973#M1946</guid>
      <dc:creator>Purushotham</dc:creator>
      <dc:date>2023-06-23T08:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Need confirmation from Palo alto on DNS Trojan ShadowPad Detected</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/need-confirmation-from-palo-alto-on-dns-trojan-shadowpad/m-p/548244#M1954</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244332"&gt;@Purushotham&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;If you have support account you can access &lt;SPAN data-reactid=".0.0.1.3"&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt; where you can search available PAN signatures/protections. If you search for "ShadowPad" - &lt;A href="https://threatvault.paloaltonetworks.com/?query=ShadowPad&amp;amp;type=" target="_blank"&gt;https://threatvault.paloaltonetworks.com/?query=ShadowPad&amp;amp;type=&lt;/A&gt; only AV signatures are available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you provide more details on the alert your customer have received?&lt;/P&gt;
&lt;P&gt;- What device has triggered this alert?&lt;/P&gt;
&lt;P&gt;- What this alert is detecting? What traffic has triggered this alert?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. TLS Version 1.1 Protocol Deprecated - Need to Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It is not very clear what you are trying to do, but I would assume you want to restrict TLS 1.1 traffic over PAN firewall. If that is a case you need to define SSL decryption profile - &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-concepts/ssl-protocol-settings-decryption-profile" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-concepts/ssl-protocol-settings-decryption-profile&lt;/A&gt; As you can see you can only do this only for decrypted traffic.&lt;/P&gt;
&lt;P&gt;1. Create SSL decryption profile&lt;/P&gt;
&lt;P&gt;2. Configure SSL protocol settings to match your requirements - min=TLS 1.2 and max=max (this will tell the FW to use the latest which it could support at the moment is 1.3, if in the future OS is updated to support higher it will automatically apply that)&lt;/P&gt;
&lt;P&gt;3. Create SSL decryption rule matching the traffic for which you want to enforce TLS1.2/1.3 and set action to decrypt, selecting the profile you created earlier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3.IP Forwarding Enabled - Need to disable IP forwarding.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This questions is not clear at all. It looks like finding from vulnerability scan or PenTest from endpoint. In order to assist you we will need little bit more clarification and background info.&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 13:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/need-confirmation-from-palo-alto-on-dns-trojan-shadowpad/m-p/548244#M1954</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-07-05T13:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Need confirmation from Palo alto on DNS Trojan ShadowPad Detected</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/need-confirmation-from-palo-alto-on-dns-trojan-shadowpad/m-p/548730#M1957</link>
      <description>&lt;P&gt;Hi Alex,&lt;BR /&gt;&lt;BR /&gt;Thank You for the response. I have opened a case with TAC and it is being addressed accordingly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 07:10:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/need-confirmation-from-palo-alto-on-dns-trojan-shadowpad/m-p/548730#M1957</guid>
      <dc:creator>Purushotham</dc:creator>
      <dc:date>2023-07-10T07:10:20Z</dc:date>
    </item>
  </channel>
</rss>

