<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exception for DNS signature which is showing the ID as 0 and FQDN as un in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338176#M904</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93126"&gt;@hisingh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.Please find the detailed threat log for ID &lt;STRONG&gt;68360795&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Detailed THreat Logsss.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26745i0A1AFD32847FC82F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Detailed THreat Logsss.png" alt="Detailed THreat Logsss.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;as&amp;nbsp; mentioned before most &lt;STRONG&gt;68360795 &lt;/STRONG&gt;is unknow in my firewall also most of the signatures are unknown. I checked in another firewall which is having same content version&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Content Version.JPG" style="width: 254px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26746i184E72F5CB9FC29B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Content Version.JPG" alt="Content Version.JPG" /&gt;&lt;/span&gt; and i can see the&lt;STRONG&gt; 68360795 &lt;/STRONG&gt;is&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS-Sinkholing-From another firewall.jpg" style="width: 769px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26747iC96699126A5ECA0B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DNS-Sinkholing-From another firewall.jpg" alt="DNS-Sinkholing-From another firewall.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;visible.But same in my firewall showing as unknown.If you can check the previous screenshots related to exception you can see the ID eg:&amp;nbsp;327772845 which is also showing as unknown.For confirming please check this ID in your FW&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 18:14:21 GMT</pubDate>
    <dc:creator>CyberEye</dc:creator>
    <dc:date>2020-07-13T18:14:21Z</dc:date>
    <item>
      <title>Exception for DNS signature which is showing the ID as 0 and FQDN as unknow</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/337954#M899</link>
      <description>&lt;P&gt;Getting false positive for the Link tivoli.com.qa as threat name(68360795).Its getting DNS sinkholing.Can anyone help to know how we&amp;nbsp; give the exception only for the threat ID 68360795 and the Fqdn is tivoli.com.qa. Attached screenshots below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS-Sinkholing-tivoli.png" style="width: 631px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26733i18D1285D460DE9A8/image-dimensions/631x142/is-moderation-mode/true?v=v2" width="631" height="142" role="button" title="DNS-Sinkholing-tivoli.png" alt="DNS-Sinkholing-tivoli.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Antispyware Policy-tivoli.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26734i27FC6D10F93D149E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Antispyware Policy-tivoli.png" alt="Antispyware Policy-tivoli.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 15:18:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/337954#M899</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2020-07-12T15:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for DNS signature which is showing the ID as 0 and FQDN as un</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338070#M900</link>
      <description>&lt;P&gt;The firewall which am using shows an the signature's name as unknown signature and FQDN as showing as unknown-fqdn&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 12:52:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338070#M900</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2020-07-13T12:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for DNS signature which is showing the ID as 0 and FQDN as un</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338124#M901</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77062"&gt;@CyberEye&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This seems to be a signature due to DNS security. Can you post the detailed threat logs so I can confirm?&lt;/P&gt;
&lt;P&gt;Also, this signature is been replaced that means it is not included in the current release, you should not have any issue with this signature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best&lt;/P&gt;
&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 15:38:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338124#M901</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-07-13T15:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for DNS signature which is showing the ID as 0 and FQDN as un</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338157#M902</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93126"&gt;@hisingh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes the&amp;nbsp;&lt;SPAN&gt;signature due to DNS security.The firewall which am using all the signatures are currently showing as unknown signature and Unknown fqdn. Attached&amp;nbsp;screenshot below&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS_Sig.png" style="width: 683px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26744i0430F0FF3EF29616/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DNS_Sig.png" alt="DNS_Sig.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Same i checked another firewall which is having same AV nd APT versions. Am also trying to give an exception for &lt;STRONG&gt;68360795&lt;/STRONG&gt; but which also showing as unknown in my FW.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 16:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338157#M902</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2020-07-13T16:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for DNS signature which is showing the ID as 0 and FQDN as un</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338165#M903</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please share the&lt;EM&gt;&lt;STRONG&gt; detailed threat logs,&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt; you have shared the spyware security profile -&amp;gt; threat exception. I am looking for monitor-&amp;gt;threat logs-&amp;gt; detailed view.&lt;/P&gt;
&lt;P&gt;Also, this signature is replaced so you will have no issue within it.&lt;/P&gt;
&lt;P&gt;Finally, please check this:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPdBCAW&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPdBCAW&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best&lt;/P&gt;
&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 17:21:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338165#M903</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-07-13T17:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for DNS signature which is showing the ID as 0 and FQDN as un</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338176#M904</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93126"&gt;@hisingh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.Please find the detailed threat log for ID &lt;STRONG&gt;68360795&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Detailed THreat Logsss.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26745i0A1AFD32847FC82F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Detailed THreat Logsss.png" alt="Detailed THreat Logsss.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;as&amp;nbsp; mentioned before most &lt;STRONG&gt;68360795 &lt;/STRONG&gt;is unknow in my firewall also most of the signatures are unknown. I checked in another firewall which is having same content version&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Content Version.JPG" style="width: 254px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26746i184E72F5CB9FC29B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Content Version.JPG" alt="Content Version.JPG" /&gt;&lt;/span&gt; and i can see the&lt;STRONG&gt; 68360795 &lt;/STRONG&gt;is&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS-Sinkholing-From another firewall.jpg" style="width: 769px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26747iC96699126A5ECA0B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DNS-Sinkholing-From another firewall.jpg" alt="DNS-Sinkholing-From another firewall.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;visible.But same in my firewall showing as unknown.If you can check the previous screenshots related to exception you can see the ID eg:&amp;nbsp;327772845 which is also showing as unknown.For confirming please check this ID in your FW&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 18:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338176#M904</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2020-07-13T18:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for DNS signature which is showing the ID as 0 and FQDN as un</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338517#M905</link>
      <description>&lt;P&gt;Did you check the threat vault connectivity from PA devices.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Test connectivity to the Threat Vault using:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;test threat-vault connection&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;or you can check it from System logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PM0BCAW" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PM0BCAW&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 19:39:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338517#M905</guid>
      <dc:creator>NijithPN</dc:creator>
      <dc:date>2020-07-14T19:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for DNS signature which is showing the ID as 0 and FQDN as un</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338520#M906</link>
      <description>&lt;P&gt;Hi Nijith,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your commments. Now its working after changing the DNS to public.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 19:56:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/exception-for-dns-signature-which-is-showing-the-id-as-0-and/m-p/338520#M906</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2020-07-14T19:56:16Z</dc:date>
    </item>
  </channel>
</rss>

