<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Stop vulnerability scanning based on app-id in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/stop-vulnerability-scanning-based-on-app-id/m-p/165106#M40</link>
    <description>&lt;P&gt;We have created a custom app id for internal only traffic that is currently generating false positives in our vulnerability scanning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We ideally would like to stop this particular app-id from being scanned for vulnerabilites or at least a specific vulnerability. Unfortunately I've found no way to create an exception based on ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application Override would suit us but from the documentation, I gather the signature of the app isn't processed and only the criterea specified in the override. We often seem to look at creating exceptions but the options for this at least appear to me to be too non-specific.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone provide some insight?&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2017 03:40:11 GMT</pubDate>
    <dc:creator>illuzian</dc:creator>
    <dc:date>2017-07-07T03:40:11Z</dc:date>
    <item>
      <title>Stop vulnerability scanning based on app-id</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/stop-vulnerability-scanning-based-on-app-id/m-p/165106#M40</link>
      <description>&lt;P&gt;We have created a custom app id for internal only traffic that is currently generating false positives in our vulnerability scanning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We ideally would like to stop this particular app-id from being scanned for vulnerabilites or at least a specific vulnerability. Unfortunately I've found no way to create an exception based on ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application Override would suit us but from the documentation, I gather the signature of the app isn't processed and only the criterea specified in the override. We often seem to look at creating exceptions but the options for this at least appear to me to be too non-specific.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone provide some insight?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 03:40:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/stop-vulnerability-scanning-based-on-app-id/m-p/165106#M40</guid>
      <dc:creator>illuzian</dc:creator>
      <dc:date>2017-07-07T03:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Stop vulnerability scanning based on app-id</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/stop-vulnerability-scanning-based-on-app-id/m-p/165367#M41</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/68290"&gt;@illuzian&lt;/a&gt;@&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After you create the custom app, and the application override policy, you can create a security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the security policy, you will specify the custom application you just created, but you will not apply any security profile. This will avoid the application from being scanned by the IPS engine. Remeber that you can be selective, and apply other profiles if you need too.&lt;/P&gt;&lt;P&gt;Since it is an internal application, and you seem to trust it, if performance is an issue, I would create this security policy with the DSRI feature in disabled state.&lt;/P&gt;&lt;P&gt;A session on the firewall comprises two flows, client to server and server to client. The DSRI feature on the Palo Alto Networks firewall can be enabled to skip the inspection of the Server to Client flow.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Using-DSRI-with-the-Palo-Alto-Networks-firewall/ta-p/70666" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Using-DSRI-with-the-Palo-Alto-Networks-firewall/ta-p/70666&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2017 18:21:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/stop-vulnerability-scanning-based-on-app-id/m-p/165367#M41</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-07-08T18:21:11Z</dc:date>
    </item>
  </channel>
</rss>

