<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decrypt STARTTLS  SMTP protocol  but not blocked Virus File in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-starttls-smtp-protocol-but-not-blocked-virus-file/m-p/593591#M118139</link>
    <description>&lt;P&gt;PAN-OS version is 10.2.9-h1 .&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jul 2024 04:48:35 GMT</pubDate>
    <dc:creator>Hogewo</dc:creator>
    <dc:date>2024-07-31T04:48:35Z</dc:date>
    <item>
      <title>Decrypt STARTTLS  SMTP protocol  but not blocked Virus File</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-starttls-smtp-protocol-but-not-blocked-virus-file/m-p/593590#M118138</link>
      <description>&lt;P&gt;The mail server resides on the network inside PaloAlto.&lt;BR /&gt;I am trying to add a feature to use STARTTLS for SMTP/25 from the mail server to the Internet.&lt;/P&gt;
&lt;P&gt;I implemented STARTTLS decryption (Forward Proxy) on the PaloAlto and sent an email with Eicar Virus to the Internet via the mail server and it was sent without being blocked.&lt;/P&gt;
&lt;P&gt;The PaloAlto threat log shows that the Virus is recognized and the Action shows “reset-both”, but it is not actually blocked.&lt;/P&gt;
&lt;P&gt;As a test, I disabled STARTTLS on the mail server, and the mail with Eicar was blocked. (However, this time it was simply TCP RESET, not the 541 code, so we recognize this as a problem as well.)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;What do you think is the cause?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 04:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-starttls-smtp-protocol-but-not-blocked-virus-file/m-p/593590#M118138</guid>
      <dc:creator>Hogewo</dc:creator>
      <dc:date>2024-07-31T04:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt STARTTLS  SMTP protocol  but not blocked Virus File</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-starttls-smtp-protocol-but-not-blocked-virus-file/m-p/593591#M118139</link>
      <description>&lt;P&gt;PAN-OS version is 10.2.9-h1 .&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 04:48:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-starttls-smtp-protocol-but-not-blocked-virus-file/m-p/593591#M118139</guid>
      <dc:creator>Hogewo</dc:creator>
      <dc:date>2024-07-31T04:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt STARTTLS  SMTP protocol  but not blocked Virus File</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-starttls-smtp-protocol-but-not-blocked-virus-file/m-p/599045#M119154</link>
      <description>&lt;P&gt;After contacting the PaloAlto Support team, it was determined that this phenomenon is a PAN-OS issue.&lt;BR /&gt;At this time, PaloAtlo continues to send SMTP emails using STARTTLS communication even after malware/viruses have been detected.&lt;/P&gt;
&lt;P&gt;PaloAlto is currently working on a patch to correct this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 00:29:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-starttls-smtp-protocol-but-not-blocked-virus-file/m-p/599045#M119154</guid>
      <dc:creator>Hogewo</dc:creator>
      <dc:date>2024-09-30T00:29:11Z</dc:date>
    </item>
  </channel>
</rss>

