<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Prevention Rules, Exceptions, Default Actions Precedence in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-prevention-rules-exceptions-default-actions-precedence/m-p/554781#M1989</link>
    <description>&lt;P&gt;Yes, that should be how it works. Please report it here if you actually get a different result.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Aug 2023 04:49:24 GMT</pubDate>
    <dc:creator>ymiyashita</dc:creator>
    <dc:date>2023-08-23T04:49:24Z</dc:date>
    <item>
      <title>Threat Prevention Rules, Exceptions, Default Actions Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-prevention-rules-exceptions-default-actions-precedence/m-p/554735#M1988</link>
      <description>&lt;P&gt;I want to confirm the order of precedence for security profile rules, default actions, and exceptions.&amp;nbsp; For example, the default action for the&amp;nbsp;SSH User Authentication Brute Force Attempt threat is alert.&amp;nbsp; However, the threat profile rule associated (simple-server-high) has an action of reset-both.&amp;nbsp; I think the rule action will override the default action of the signature meaning that the action of reset-both will be taken.&amp;nbsp; Is that correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a follow up, in that scenario I also have exceptions for a few IPs with that use the default action of alert.&amp;nbsp; I think the exception will take precedence and the action will be to alert.&amp;nbsp; Is that correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To summarize, I think rules override the default action but exceptions override both the rules and original default action when an exception is enabled.&amp;nbsp; Is that correct?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 17:54:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-prevention-rules-exceptions-default-actions-precedence/m-p/554735#M1988</guid>
      <dc:creator>bruce.johnson</dc:creator>
      <dc:date>2023-08-22T17:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rules, Exceptions, Default Actions Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-prevention-rules-exceptions-default-actions-precedence/m-p/554781#M1989</link>
      <description>&lt;P&gt;Yes, that should be how it works. Please report it here if you actually get a different result.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 04:49:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-prevention-rules-exceptions-default-actions-precedence/m-p/554781#M1989</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2023-08-23T04:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rules, Exceptions, Default Actions Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-prevention-rules-exceptions-default-actions-precedence/m-p/595569#M2262</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9239" target="_self" aria-label="View Profile of bruce.johnson"&gt;&lt;/A&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9239"&gt;@bruce.johnson&lt;/a&gt;,&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9239" target="_self" aria-label="View Profile of bruce.johnson"&gt;&lt;SPAN class=""&gt; yes you are absolutely right. i have tested and found it okay&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 22 Aug 2024 04:44:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-prevention-rules-exceptions-default-actions-precedence/m-p/595569#M2262</guid>
      <dc:creator>Rokibul</dc:creator>
      <dc:date>2024-08-22T04:44:34Z</dc:date>
    </item>
  </channel>
</rss>

