<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reconnaissance Protection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reconnaissance-protection/m-p/18539#M13537</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi : In regard to the settings for Port Scans and Host Sweeps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What counts as an event toward reaching the threshold? Is it a SYN packet or are other types of packets counted?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Jan 2012 21:04:47 GMT</pubDate>
    <dc:creator>wlu</dc:creator>
    <dc:date>2012-01-11T21:04:47Z</dc:date>
    <item>
      <title>Reconnaissance Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconnaissance-protection/m-p/18539#M13537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi : In regard to the settings for Port Scans and Host Sweeps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What counts as an event toward reaching the threshold? Is it a SYN packet or are other types of packets counted?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jan 2012 21:04:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconnaissance-protection/m-p/18539#M13537</guid>
      <dc:creator>wlu</dc:creator>
      <dc:date>2012-01-11T21:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Reconnaissance Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reconnaissance-protection/m-p/18540#M13538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Zone Protection doc here covers this Reconnaissance protection on page 4:&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3581" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It states:&lt;/P&gt;&lt;P&gt;"Reconnaissance protection is used to prevent/alert administrators on reconnaissance attempts like ports scans, ICMP sweep. Unlike the flood settings, threshold settings are applicable to hosts in the zone where reconnaissance protection is configured.Interval: Time between successive probes for open ports. For host sweep it is the time interval between successive probes (ICMP/TCP/UDP) to the network"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, Since TCP uses SYN, that should count for TCP, and as far as other protocols ICMP and UDP they do not have SYN packets, but are covered by this protection, so that should also be covered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that makes a little sense.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 21:48:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reconnaissance-protection/m-p/18540#M13538</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-24T21:48:31Z</dc:date>
    </item>
  </channel>
</rss>

