<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP SYN with data Threat logs in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tcp-syn-with-data-threat-logs/m-p/206022#M280</link>
    <description>&lt;P&gt;If the firewall detects a TCP packet with data and your Zone Protection profile is set to drop these, then I wouldn't think it is a false positive. It triggers the protection because the firewall sees these.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More information available at:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/networking-features/zone-protection-for-syn-data-payloads" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/networking-features/zone-protection-for-syn-data-payloads&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is currently no way to inhibit these protections from writing to the Threat Logs, however, if you receive the alerts through a Log Forwarding profile, you can edit the profile so that these are not forwarded out using a Filter in PAN-OS 8.0:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(severity eq informational) and (threatid neq 8723)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Selective Log Forwarding&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/management-features/selective-log-forwarding-based-on-log-attributes" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/management-features/selective-log-forwarding-based-on-log-attributes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Video Tutorial&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/Tutorial-Filtered-Log-Forwarding/ta-p/145950" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tutorials/Tutorial-Filtered-Log-Forwarding/ta-p/145950&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Mar 2018 17:02:02 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2018-03-16T17:02:02Z</dc:date>
    <item>
      <title>TCP SYN with data Threat logs</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tcp-syn-with-data-threat-logs/m-p/205959#M279</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I receive hundreds of &lt;STRONG&gt;TCP SYN with data&lt;/STRONG&gt; Threat Alerts from my BYOD zone every day. I was learning more about it and I understood that it is a TCP syn packet with data in its payload. However, as almost all of them seems to come from non-malicious sources, I am not sure if I should worry about it or just consider it as a false positive and tweak my firewall.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any advice would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Leandro Ramos&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 15:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tcp-syn-with-data-threat-logs/m-p/205959#M279</guid>
      <dc:creator>leandro.ramos</dc:creator>
      <dc:date>2018-03-16T15:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYN with data Threat logs</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tcp-syn-with-data-threat-logs/m-p/206022#M280</link>
      <description>&lt;P&gt;If the firewall detects a TCP packet with data and your Zone Protection profile is set to drop these, then I wouldn't think it is a false positive. It triggers the protection because the firewall sees these.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More information available at:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/networking-features/zone-protection-for-syn-data-payloads" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/networking-features/zone-protection-for-syn-data-payloads&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is currently no way to inhibit these protections from writing to the Threat Logs, however, if you receive the alerts through a Log Forwarding profile, you can edit the profile so that these are not forwarded out using a Filter in PAN-OS 8.0:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(severity eq informational) and (threatid neq 8723)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Selective Log Forwarding&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/management-features/selective-log-forwarding-based-on-log-attributes" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/management-features/selective-log-forwarding-based-on-log-attributes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Video Tutorial&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/Tutorial-Filtered-Log-Forwarding/ta-p/145950" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tutorials/Tutorial-Filtered-Log-Forwarding/ta-p/145950&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 17:02:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tcp-syn-with-data-threat-logs/m-p/206022#M280</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-03-16T17:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYN with data Threat logs</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tcp-syn-with-data-threat-logs/m-p/206254#M283</link>
      <description>&lt;P&gt;Hi Mivaldi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for all the information provided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Leandro Ramos&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 08:13:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tcp-syn-with-data-threat-logs/m-p/206254#M283</guid>
      <dc:creator>leandro.ramos</dc:creator>
      <dc:date>2018-03-19T08:13:46Z</dc:date>
    </item>
  </channel>
</rss>

