<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reset-Both for client/sftp server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560239#M113579</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221132"&gt;@RiveraMarco&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Whatever vulnerability profile is assigned to the security policy matching that traffic can be updated with an exception if you feel like that's the right course of action. Ideally you would build out a specific entry for that traffic and assign it it's own profile if you proceed with that exception.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Oct 2023 14:49:36 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-10-02T14:49:36Z</dc:date>
    <item>
      <title>Reset-Both for client/sftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560034#M113555</link>
      <description>&lt;P&gt;I have been noticing lots of traffic between an internal client to one of our Sftp server where the log states&lt;/P&gt;
&lt;P&gt;SSH User Authentication Brute Force on Port 22&amp;nbsp; - Action Reset-Both.&amp;nbsp; We have checked the client and has the correct credentials for the destination.&amp;nbsp; What else should I check?&amp;nbsp; The logs on the sftp server do not indicate any errors.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 13:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560034#M113555</guid>
      <dc:creator>RiveraMarco</dc:creator>
      <dc:date>2023-09-29T13:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Reset-Both for client/sftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560035#M113556</link>
      <description>&lt;P&gt;Maybe you are transferring small files and client logs into SFTP server every time to transfer file.&lt;/P&gt;
&lt;P&gt;By default&amp;nbsp;&lt;SPAN&gt;SSH User Authentication Brute Force matches if there are more than 20 login events during 60 second period.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 13:26:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560035#M113556</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-29T13:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Reset-Both for client/sftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560041#M113557</link>
      <description>&lt;P&gt;Your explanation sounds reasonable.&amp;nbsp; How should we address this so we don't see the traffic?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 14:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560041#M113557</guid>
      <dc:creator>RiveraMarco</dc:creator>
      <dc:date>2023-09-29T14:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Reset-Both for client/sftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560239#M113579</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221132"&gt;@RiveraMarco&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Whatever vulnerability profile is assigned to the security policy matching that traffic can be updated with an exception if you feel like that's the right course of action. Ideally you would build out a specific entry for that traffic and assign it it's own profile if you proceed with that exception.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 14:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-both-for-client-sftp-server/m-p/560239#M113579</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-10-02T14:49:36Z</dc:date>
    </item>
  </channel>
</rss>

