<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Automatic IP block-list PAN 8.0 in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/209439#M298</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&amp;nbsp;am wondering if there is any way to let's say block the IP address from a source for a set period of time.&amp;nbsp; An example of this could be, we are being attack, same IP address hitting our firewall a 100 times in 3 minutes, It is being reported as "code execution vulnerability."&amp;nbsp; Now the action is dropped, but the IP address could be running some other exploit at the same time, and not recognized by the firewall as such or maybe it is.&amp;nbsp; I am looking for a way to automate a process by which we can setup some kind of rule to block that IP address, of the source, for a set period of time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basic I am looking for a way to say look I am being hit by this IP on multiple ports and they are for different services all with let say 2 minutes.&amp;nbsp; I want to be able to automatically block that source for let say 5-10 minutes to see if it happens again and if it does the add it to the external block-list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any assistance would be greatly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Apr 2018 15:19:33 GMT</pubDate>
    <dc:creator>ebenditt1</dc:creator>
    <dc:date>2018-04-10T15:19:33Z</dc:date>
    <item>
      <title>Automatic IP block-list PAN 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/209439#M298</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&amp;nbsp;am wondering if there is any way to let's say block the IP address from a source for a set period of time.&amp;nbsp; An example of this could be, we are being attack, same IP address hitting our firewall a 100 times in 3 minutes, It is being reported as "code execution vulnerability."&amp;nbsp; Now the action is dropped, but the IP address could be running some other exploit at the same time, and not recognized by the firewall as such or maybe it is.&amp;nbsp; I am looking for a way to automate a process by which we can setup some kind of rule to block that IP address, of the source, for a set period of time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basic I am looking for a way to say look I am being hit by this IP on multiple ports and they are for different services all with let say 2 minutes.&amp;nbsp; I want to be able to automatically block that source for let say 5-10 minutes to see if it happens again and if it does the add it to the external block-list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any assistance would be greatly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2018 15:19:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/209439#M298</guid>
      <dc:creator>ebenditt1</dc:creator>
      <dc:date>2018-04-10T15:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic IP block-list PAN 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/209440#M299</link>
      <description>&lt;P&gt;You can do this by configuring a Threat Exception and changing the Action to block-ip.&lt;/P&gt;
&lt;P&gt;You can define the block time for the block-ip action.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are a couple KB's on this subject:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/How-to-Block-A-Threat-For-a-Specific-Time-Interval/tac-p/149397#M240" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/How-to-Block-A-Threat-For-a-Specific-Time-Interval/tac-p/149397#M240&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/customize-the-action-and-trigger-conditions-for-a-brute-force-signature.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/customize-the-action-and-trigger-conditions-for-a-brute-force-signature.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2018 15:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/209440#M299</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-04-10T15:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic IP block-list PAN 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/209510#M303</link>
      <description>&lt;P&gt;With Block-IP you can drop traffic for a defined period, between 1 and 3600 seconds. Take care when apply because legitimate sources could&amp;nbsp;also be blocked.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 07:23:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/209510#M303</guid>
      <dc:creator>ACortes</dc:creator>
      <dc:date>2018-04-11T07:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic IP block-list PAN 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/387217#M1079</link>
      <description>&lt;P&gt;This maybe of use to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check it out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.smartcloudcomputing.net/2021/02/22/how-to-automatically-blacklist-an-attackers-ip-on-palo-alto/" target="_blank"&gt;https://www.smartcloudcomputing.net/2021/02/22/how-to-automatically-blacklist-an-attackers-ip-on-palo-alto/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 18:58:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/automatic-ip-block-list-pan-8-0/m-p/387217#M1079</guid>
      <dc:creator>Ricardo-GTZ</dc:creator>
      <dc:date>2021-02-22T18:58:25Z</dc:date>
    </item>
  </channel>
</rss>

