<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Honeypot - block IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/honeypot-block-ips/m-p/541570#M110998</link>
    <description>&lt;P&gt;We are looking at creating a Honeypot Website. The idea is to set it up with a much more restricted vulnerability profile so when hackers are scanning for certain vulnerabilities in the low and informational category their IP is blocked. The question I have is whether this is a global block, as in that IP would be blocked from hitting any externally facing site, or it will only be blocked from the honeypot. I assume it is globally by documentation, but want to make sure.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2023 14:11:04 GMT</pubDate>
    <dc:creator>craymond</dc:creator>
    <dc:date>2023-05-09T14:11:04Z</dc:date>
    <item>
      <title>Honeypot - block IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/honeypot-block-ips/m-p/541570#M110998</link>
      <description>&lt;P&gt;We are looking at creating a Honeypot Website. The idea is to set it up with a much more restricted vulnerability profile so when hackers are scanning for certain vulnerabilities in the low and informational category their IP is blocked. The question I have is whether this is a global block, as in that IP would be blocked from hitting any externally facing site, or it will only be blocked from the honeypot. I assume it is globally by documentation, but want to make sure.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 14:11:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/honeypot-block-ips/m-p/541570#M110998</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2023-05-09T14:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Honeypot - block IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/honeypot-block-ips/m-p/541575#M110999</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28274"&gt;@craymond&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;By default the traffic would just be blocked. You'll want to take a look at auto-tagging and use the associated tag to deny the traffic however you want within your environment. Alternatively you could also use the XML API to perform the same thing if you didn't want to deal with Auto-Tagging.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/use-auto-tagging-to-automate-security-actions" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/use-auto-tagging-to-automate-security-actions#idbd42a246-f8f3-4ddc-9487-f086d3d36f1c&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 14:52:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/honeypot-block-ips/m-p/541575#M110999</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-05-09T14:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Honeypot - block IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/honeypot-block-ips/m-p/541608#M111002</link>
      <description>&lt;P&gt;Thank you BPry - The autotagging feature is a great idea.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 17:56:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/honeypot-block-ips/m-p/541608#M111002</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2023-05-09T17:56:56Z</dc:date>
    </item>
  </channel>
</rss>

