<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCI Compliance - 86476 Web Server Stopped Responding in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229337#M124323</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16234"&gt;@cenders&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for info, I am not sure, what method they are using to scan, if they are scanning the network behind your firewall then you have to open the requested ports to pass through the traffic from firewall.&lt;/P&gt;
&lt;P&gt;Second if they are scanning your firewall exposed Public IPs, then you don't need to do anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Third if they are scanning firewall itself with logging to firewall then you have to allow the firewall access to there IP's to ssh / https the device for further scanning.&lt;/P&gt;</description>
    <pubDate>Sat, 17 May 2025 00:30:01 GMT</pubDate>
    <dc:creator>mshekh</dc:creator>
    <dc:date>2025-05-17T00:30:01Z</dc:date>
    <item>
      <title>PCI Compliance - 86476 Web Server Stopped Responding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229275#M124314</link>
      <description>&lt;P&gt;First time in years, getting this failed result to a PCI scan.&amp;nbsp;86476 Web Server Stopped Responding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Their tech suggests it has something to do with my PAN WAF/IDS and they have a bunch of IP addresses/ranges that I can whitelist. I find this odd as I've never had to whitelist them before and I've passed many many scans prior to this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do I whitelist the&amp;nbsp;Sysnet servers from any sort of WAF when they scan my external IP address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is this some sort of glitch in their scanner.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 14:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229275#M124314</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2025-05-16T14:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance - 86476 Web Server Stopped Responding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229337#M124323</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16234"&gt;@cenders&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for info, I am not sure, what method they are using to scan, if they are scanning the network behind your firewall then you have to open the requested ports to pass through the traffic from firewall.&lt;/P&gt;
&lt;P&gt;Second if they are scanning your firewall exposed Public IPs, then you don't need to do anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Third if they are scanning firewall itself with logging to firewall then you have to allow the firewall access to there IP's to ssh / https the device for further scanning.&lt;/P&gt;</description>
      <pubDate>Sat, 17 May 2025 00:30:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229337#M124323</guid>
      <dc:creator>mshekh</dc:creator>
      <dc:date>2025-05-17T00:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance - 86476 Web Server Stopped Responding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229540#M124340</link>
      <description>&lt;P&gt;It is an external scan, scanning the exposed public IP for any vulnerabilities.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 19:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229540#M124340</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2025-05-20T19:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance - 86476 Web Server Stopped Responding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229567#M124341</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16234"&gt;@cenders&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for info, If public facing IP's are allowed for specific source then you have to add those IP, if you have source any then you don't need to make any config change at your end...&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 02:32:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pci-compliance-86476-web-server-stopped-responding/m-p/1229567#M124341</guid>
      <dc:creator>mshekh</dc:creator>
      <dc:date>2025-05-21T02:32:18Z</dc:date>
    </item>
  </channel>
</rss>

