<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Severity High and medium action are getting allow instead of block in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/365640#M984</link>
    <description>&lt;P&gt;URL's are HTTP traffic, so they don't get sinkholed. URL's are subject to URL Filtering.&lt;/P&gt;
&lt;P&gt;Sinkhole is applied to domains, which is DNS traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please open a Support case so we can work with you and understand the question better.&lt;/P&gt;
&lt;P&gt;We can come back to this post at the end of the case to share our findings with the community.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2020 18:40:34 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2020-11-25T18:40:34Z</dc:date>
    <item>
      <title>Severity High and medium action are getting allow instead of block</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/364185#M978</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;After upgrade to 9.1.5, i noticed the Severity level high and medium threat actions are allowed and some of them are getting sinkhole. Please let us know if anyone knows why it's getting alert instead of the block in high severity. Attached screenshots&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS-Issue-Not block.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28717i03BDE17C490B9529/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DNS-Issue-Not block.png" alt="DNS-Issue-Not block.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 16:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/364185#M978</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2020-11-19T16:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Severity High and medium action are getting allow instead of block</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/364596#M979</link>
      <description>&lt;P&gt;The Severity based rules are for Anti-Spyware. There is no Severity based rules for Anti-Spyware DNS.&lt;/P&gt;
&lt;P&gt;For Anti-Spyware DNS, you define actions based on Content DNS signatures, DNS Security DNS Categories, or EDL's of type Domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 20:36:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/364596#M979</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-11-20T20:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Severity High and medium action are getting allow instead of block</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/364615#M980</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34186"&gt;@mivaldi&lt;/a&gt;&amp;nbsp;thanks for reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So is this expected behaviour? The same url it's getting sinkhole alternatively. I cross checked same in other firewall which is running 9.0 os and confirmed all the high, Medium and critical named as DGA Domain and spyware type are sinkholed.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 21:10:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/364615#M980</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2020-11-20T21:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Severity High and medium action are getting allow instead of block</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/365640#M984</link>
      <description>&lt;P&gt;URL's are HTTP traffic, so they don't get sinkholed. URL's are subject to URL Filtering.&lt;/P&gt;
&lt;P&gt;Sinkhole is applied to domains, which is DNS traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please open a Support case so we can work with you and understand the question better.&lt;/P&gt;
&lt;P&gt;We can come back to this post at the end of the case to share our findings with the community.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 18:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/severity-high-and-medium-action-are-getting-allow-instead-of/m-p/365640#M984</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-11-25T18:40:34Z</dc:date>
    </item>
  </channel>
</rss>

