<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unblock IP address after threat triggered block-ip in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15651#M11459</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's really weird because the show dos-protection / clear dos-protection commands work perfectly in my environment... even when triggered from vulnerability protection signatures such as brute-force SSH.&amp;nbsp; Here's how I'm testing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From a client to a server, I setup a constant ping.&amp;nbsp; Then, from the same client, I initiated a brute-force SSH attack against that same server.&amp;nbsp; As soon as the brute-force signature is triggered, the pings stop as expected.&amp;nbsp; From here "show dos-protection..." shows the client's blocked IP address.&amp;nbsp; Once I "clear dos-protection", the pings start back up again.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either this is a difference in how a specific platform behaves (I'm using a VM-300), a PAN-OS code version difference, or you're testing this differently.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 12 Apr 2015 19:50:21 GMT</pubDate>
    <dc:creator>jvalentine</dc:creator>
    <dc:date>2015-04-12T19:50:21Z</dc:date>
    <item>
      <title>Unblock IP address after threat triggered block-ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15647#M11455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Suppose a long time value was set for a threat where one had set the action to block-ip - say 10 minutes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way via the CLI or GUI to see the list of IP addresses that are blocked due to the threat engine?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Better still, is there a way to clear that list, or selectively clear IP addresses?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Apr 2015 20:45:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15647#M11455</guid>
      <dc:creator>SimonBlackler</dc:creator>
      <dc:date>2015-04-11T20:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unblock IP address after threat triggered block-ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15648#M11456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;STRONG&gt;show dos-protection zone untrust blocked source&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt; Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Zone&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocked IP TTL(sec)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;--------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;----------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; untrust&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 166.70.8.4,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-size: 13.3333330154419px; font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;STRONG&gt;clear dos-protection zone untrust blocked &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;&amp;gt; &lt;STRONG&gt;all&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all IPs&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;&amp;gt; &lt;STRONG&gt;source&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; Specify Source IP(s) to unblock&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;STRONG&gt;clear dos-protection zone untrust blocked source 166.70.8.4 &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-size: 13.3333330154419px; font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-size: 13.3333330154419px; font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;/SPAN&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;STRONG&gt;show dos-protection zone untrust blocked source&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt; Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Zone&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocked IP TTL(sec)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;--------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;SPAN class="s1" style="font-family: 'andale mono', times;"&gt;----------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'andale mono', times;"&gt;admin@pa0(active)&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Apr 2015 03:34:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15648#M11456</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2015-04-12T03:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unblock IP address after threat triggered block-ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15649#M11457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jared, I'm already familiar with those commands - sadly, they do not list IP addresses that have been blocked by specific Threat IDs. They only deal with IP blocked through the DoS counters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, Threat ID 40001 "FTP: login Brute-force attempt" - if the action for this is changed to "block-ip" IP source for 1200 seconds, and an IP gets blocked, then it is apparently not possible to subsequently unblock that IP again before the 20 minutes is up. As you can imagine, sometimes an important customer gets caught out by this when accessing from an out of band IP, and asks us to unblock it - not an unreasonable request - with which we are currently unable to comply.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Apr 2015 07:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15649#M11457</guid>
      <dc:creator>SimonBlackler</dc:creator>
      <dc:date>2015-04-12T07:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unblock IP address after threat triggered block-ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15650#M11458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;run this command to see the IP listed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;gt;debug dataplane show dos block-table&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run this command to the remove the IP. As of now I don't see a way to remove only the individual IP address. Being that these are blocked for a period of time you are less likely to have more than one IP blocked at the same time but if so this will release all of them. Then they must meet the threat criteria to be blocked again. Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;gt;debug dataplane reset dos block-table&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just test and this is how you unblock the individual IP&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;gt;debug dataplane reset dos zone L3_Untrust block-table source x.x.x.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;After running this command you may need to find the actual&amp;nbsp; session and clear it from the "Discard" State&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;admin@PA-200&amp;gt; show session all filter source x.x.x.x&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp;&amp;nbsp; Type Flag&amp;nbsp; Src[Sport]/Zone/Proto (translated IP[Port])&lt;BR /&gt;Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dst[Dport]/Zone (translated IP[Port])&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;45629&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DISCARD FLOW&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x[36437]/L3_Untrust/6&amp;nbsp; (x.x.x.x[36437])&lt;BR /&gt;vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.5[22]/L3_Untrust&amp;nbsp; (10.0.0.5[22])&lt;BR /&gt;admin@PA-200&amp;gt; clear session id 45629&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Apr 2015 18:35:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15650#M11458</guid>
      <dc:creator>jperry1</dc:creator>
      <dc:date>2015-04-12T18:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unblock IP address after threat triggered block-ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15651#M11459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's really weird because the show dos-protection / clear dos-protection commands work perfectly in my environment... even when triggered from vulnerability protection signatures such as brute-force SSH.&amp;nbsp; Here's how I'm testing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From a client to a server, I setup a constant ping.&amp;nbsp; Then, from the same client, I initiated a brute-force SSH attack against that same server.&amp;nbsp; As soon as the brute-force signature is triggered, the pings stop as expected.&amp;nbsp; From here "show dos-protection..." shows the client's blocked IP address.&amp;nbsp; Once I "clear dos-protection", the pings start back up again.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either this is a difference in how a specific platform behaves (I'm using a VM-300), a PAN-OS code version difference, or you're testing this differently.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Apr 2015 19:50:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unblock-ip-address-after-threat-triggered-block-ip/m-p/15651#M11459</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2015-04-12T19:50:21Z</dc:date>
    </item>
  </channel>
</rss>

