<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Question - Key Exchange in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17811#M12968</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm going to assume SSH is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On our External interface the management profile is: Allow_ping_ssh_https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as threat logs, I don't see any for SSH in our current logset which does not go as far back as when these SSH Handshake logs were noticed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Nov 2014 21:06:56 GMT</pubDate>
    <dc:creator>MatthewSmith</dc:creator>
    <dc:date>2014-11-18T21:06:56Z</dc:date>
    <item>
      <title>Log Question - Key Exchange</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17809#M12966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We randomly seem to get some alerts that say:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SYSTEM ALERT : high :&amp;nbsp; error: Key exchange failed in SSH handshake - DH key &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm new to Palo Alto firewalls and was just curious if this is something that can be ignored? Was thinking that this might be the result of just some networking issue this to fail and generate this alert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2014 20:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17809#M12966</guid>
      <dc:creator>MatthewSmith</dc:creator>
      <dc:date>2014-11-18T20:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Log Question - Key Exchange</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17810#M12967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have SSH enabled on the external interface of this PAN firewall. Is there any threat logs on this PAN FW Monitor &amp;gt; Logs &amp;gt; Threat.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2014 20:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17810#M12967</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-18T20:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Log Question - Key Exchange</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17811#M12968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm going to assume SSH is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On our External interface the management profile is: Allow_ping_ssh_https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as threat logs, I don't see any for SSH in our current logset which does not go as far back as when these SSH Handshake logs were noticed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2014 21:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17811#M12968</guid>
      <dc:creator>MatthewSmith</dc:creator>
      <dc:date>2014-11-18T21:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Log Question - Key Exchange</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17812#M12969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that this alert was generated because of a failed attempt to gain access to the device via SSH. If you think, someone is trying to get unauthorized access on your device, you may configure "permitted IP Addresses" list on your PAN firewall. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="permitted-list.jpg" class="image-0 jive-image" height="344" src="https://live.paloaltonetworks.com/legacyfs/online/16931_permitted-list.jpg" style="height: 343.840796019901px; width: 424px;" width="424" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 04:37:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17812#M12969</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-19T04:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Log Question - Key Exchange</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17813#M12970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok thank you. That is what I was looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 15:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17813#M12970</guid>
      <dc:creator>MatthewSmith</dc:creator>
      <dc:date>2014-11-19T15:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Log Question - Key Exchange</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17814#M12971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to reproduce this error, but wasnt successful in any configuration scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have accessive SSH attempts on firewall, this kind of error comes in DOS scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 15:23:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-question-key-exchange/m-p/17814#M12971</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-19T15:23:43Z</dc:date>
    </item>
  </channel>
</rss>

