<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone protection reconnossainse protection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reconnossainse-protection/m-p/16068#M11740</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You didn't mention what your alert and activate thresholds are set to. One thing you can do is to try lowering these values to lowest possible to ensure that the rule is having the desired affect. If they are then you can increase the values to a more real-world number. But as you mentioned that you are testing, this should help to isolate if things are working as expected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also to help verify you can look at global counters to ensure the zone protection is working. This is done via CLI with following command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter delta yes | match dos&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Mar 2013 19:35:42 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-03-25T19:35:42Z</dc:date>
    <item>
      <title>Zone protection reconnossainse protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reconnossainse-protection/m-p/16067#M11739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am testing "reconnossainse protection" feature on a PA-200. I built a reconnossainse protection profile over zone protection tab and I mark over "reconnossainse protection" and I checked "tcp port scan", "host sweep" and "udp port scan" (with default settings). I activated zone protection profile on each zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am executing "nmap" over a subnet (default zenmap settings) but PA don't detect it as a "port scan". I found PA identify that traffic like "ssl webbrowsing rule". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 15:24:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reconnossainse-protection/m-p/16067#M11739</guid>
      <dc:creator>ENAGAS</dc:creator>
      <dc:date>2013-03-25T15:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection reconnossainse protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reconnossainse-protection/m-p/16068#M11740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You didn't mention what your alert and activate thresholds are set to. One thing you can do is to try lowering these values to lowest possible to ensure that the rule is having the desired affect. If they are then you can increase the values to a more real-world number. But as you mentioned that you are testing, this should help to isolate if things are working as expected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also to help verify you can look at global counters to ensure the zone protection is working. This is done via CLI with following command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter delta yes | match dos&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 19:35:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reconnossainse-protection/m-p/16068#M11740</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-03-25T19:35:42Z</dc:date>
    </item>
  </channel>
</rss>

