<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Packet Buffer Protection (PBP) in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/packet-buffer-protection-pbp/m-p/1229172#M2446</link>
    <description>&lt;P&gt;We are receiving multiple alerts for Packet Buffer Protection (PBP) being triggered on internal-to-internal and internal-to-external traffic. My understanding is that PBP is primarily intended to protect against DoS attacks, which are typically external-to-internal in nature.&lt;BR /&gt;Is it expected behavior for PBP to be triggered by internal-to-internal or internal-to-external traffic? Should PBP be configured to monitor all traffic directions, or is it best practice to apply it mainly for external-to-internal flows? Any insight or recommendations would be appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 15 May 2025 18:19:26 GMT</pubDate>
    <dc:creator>User_707</dc:creator>
    <dc:date>2025-05-15T18:19:26Z</dc:date>
    <item>
      <title>Packet Buffer Protection (PBP)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/packet-buffer-protection-pbp/m-p/1229172#M2446</link>
      <description>&lt;P&gt;We are receiving multiple alerts for Packet Buffer Protection (PBP) being triggered on internal-to-internal and internal-to-external traffic. My understanding is that PBP is primarily intended to protect against DoS attacks, which are typically external-to-internal in nature.&lt;BR /&gt;Is it expected behavior for PBP to be triggered by internal-to-internal or internal-to-external traffic? Should PBP be configured to monitor all traffic directions, or is it best practice to apply it mainly for external-to-internal flows? Any insight or recommendations would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 18:19:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/packet-buffer-protection-pbp/m-p/1229172#M2446</guid>
      <dc:creator>User_707</dc:creator>
      <dc:date>2025-05-15T18:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Buffer Protection (PBP)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/packet-buffer-protection-pbp/m-p/1229257#M2447</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/953534295"&gt;@User_707&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for info, It's completely depends on environment and requirements. You can configure it for internal-internal or internal-to-external traffic.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;You can refer the below docs for more details:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;DoS and Zone Protection Best Practices&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/dos-and-zone-protection-best-practices/dos-and-zone-protection-best-practices/deploy-dos-and-zone-protection-using-best-practices" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/dos-and-zone-protection-best-practices/dos-and-zone-protection-best-practices/deploy-dos-and-zone-protection-using-best-practices&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Baseline CPS Measurements for Setting Flood Thresholds&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresholds" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresholds&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Zone protection profiles&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clm9CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clm9CAC&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How to Measure CPS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresholds/how-to-measure-cps" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresholds/how-to-measure-cps&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How to Verify if Zone Protection is Working&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhzCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhzCAC&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/packet-buffer-protection" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/packet-buffer-protection&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 09:37:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/packet-buffer-protection-pbp/m-p/1229257#M2447</guid>
      <dc:creator>mshekh</dc:creator>
      <dc:date>2025-05-16T09:37:33Z</dc:date>
    </item>
  </channel>
</rss>

