<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS - new signature's action set to default instead of the action specified in rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18986#M13832</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The action set in the vulnerability Rules are coherent with the default action set with individual signatures. In the exceptions tab, you just add an exception for an individual vulnerability signature and change the action according&lt;/P&gt;&lt;P&gt;to you requirements saying that exempt the action set in the Rule for this signature.&lt;/P&gt;&lt;P&gt;To see the default action set on a vulnerability signature, open the profile and navigate to exceptions tab. Check the show all signatures option which shows all the signatures with the default action associated with them. &lt;/P&gt;&lt;P&gt;Hope this is helpful and not confusing.........:)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Oct 2014 01:41:01 GMT</pubDate>
    <dc:creator>tshiv</dc:creator>
    <dc:date>2014-10-02T01:41:01Z</dc:date>
    <item>
      <title>IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18981#M13827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a general IPS profile with a rule (named block-crit,high) which includes all signatures with severity 'critical' and 'high'. Action for the rule is set to 'block'. I have automatic updates on for IPS signatures. Yesterday a new signature (&lt;SPAN style="font-size: 9.0pt; font-family: 'Tahoma','sans-serif'; color: #111111;"&gt;OpenSSL SSL/TLS MITM vulnerability&lt;/SPAN&gt;) was released with severity critical. When I checked my IPS profile today i noticed that signature was correctly included in above rule (block-crit,high) but the action for this signature was set to 'default (alert)' despite the action for rule being 'block'. &lt;/P&gt;&lt;P&gt;Is this expected behaviour? Are all new signatures set to default action? Can you set new signatures to block?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pa-ips.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13813_pa-ips.jpg" style="height: 134px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;P&gt;Simon Antonic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jun 2014 07:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18981#M13827</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-06-09T07:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18982#M13828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to my knoweladge this is OK IF your "rules" section of this profiles looks like my:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-06-09_130656.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13822_2014-06-09_130656.png" style="height: 315px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-06-09_130622.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13823_2014-06-09_130622.png" style="height: 314px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;This is example with Heartbleed because is easy to verify &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My thread log have a lot of entries like:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-06-09_130927.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/13824_2014-06-09_130927.png" style="height: 61px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;So this is proof that is working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jun 2014 11:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18982#M13828</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-06-09T11:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18983#M13829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;Yep, action in rule is on 'block'. I just wasn't 'lucky' enough to find an event triggered by this signature in logs to verify how it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still a way to check current response for certain signature would be useful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jun 2014 13:37:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18983#M13829</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-06-09T13:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18984#M13830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I've come across the same problem again and still haven't found a solution for it.&lt;/P&gt;&lt;P&gt;How do you check what is the set action for certain signature? I couldn't find a CLI command for it and in GUI when you check 'show all signatures' every signature is listed with the default action and not with the action set by rule.&lt;/P&gt;&lt;P&gt;I believe this is a very important feature and I'd really need a way to check set actions for signatures in certain profile. Waiting for an attempt of exploit which would trigger that signature to happen and checking logs afterwards is not an answer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am i gettting a 'contact your SE for feature request' answer next? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Oct 2014 08:07:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18984#M13830</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-01T08:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18985#M13831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;are you using the built in ips profiles?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Oct 2014 14:20:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18985#M13831</guid>
      <dc:creator>Jmason</dc:creator>
      <dc:date>2014-10-01T14:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18986#M13832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The action set in the vulnerability Rules are coherent with the default action set with individual signatures. In the exceptions tab, you just add an exception for an individual vulnerability signature and change the action according&lt;/P&gt;&lt;P&gt;to you requirements saying that exempt the action set in the Rule for this signature.&lt;/P&gt;&lt;P&gt;To see the default action set on a vulnerability signature, open the profile and navigate to exceptions tab. Check the show all signatures option which shows all the signatures with the default action associated with them. &lt;/P&gt;&lt;P&gt;Hope this is helpful and not confusing.........:)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Oct 2014 01:41:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18986#M13832</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-02T01:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18987#M13833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Simon, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right and that is the expected behavior. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you create a rule and choose the action for that rule to "block" for the severities "critical and high" and have chosen "Any" in the CVE and Vendor-ID column, then any CVE (even CVE whose default action is alert) will be blocked. The vulnerabilities rules and the corresponding action in that rule (for any CVE/Vendor-ID OR for specified CVE/Vendor-ID) take precedence over the default threat ID actions. Again, the rule must be matched correctly for the corresponding action to take place. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can change the default action for threat IDs. Click the "Exceptions" tab and then click "Show all signatures". Enter the threat ID in the search bar and click on the action to see the dropdown. Now choose the required action and ensure to check the "Enable" box. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Oct 2014 10:57:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18987#M13833</guid>
      <dc:creator>gchandrasekaran</dc:creator>
      <dc:date>2014-10-02T10:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18988#M13834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I understand how it works (I think). The problem is that you can't see neither in GUI nor in CLI what is the current action for certain signature. Yes, you can see the rules, you can see in which rules the signature is included, and you can figure out what the action is.&lt;/P&gt;&lt;P&gt;But there is no view which would list the signature with the current set action, unless you make it an exception. &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I know it's only a view missing and not functionality, but it would be really nice to see signature(s) listed with its current action for certain security profile like all the IPS systems have. I'd be happy already with a CLI command to check response, maybe something like "show policy security-profile 'profile_name'&amp;nbsp; AlertID 'ID_number' " and the output is signature name and set action for that profile. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Oct 2014 11:53:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18988#M13834</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-02T11:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18989#M13835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Simon, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As of now, the options to view the default action is by checking "Show all signatures" in the Exceptions tab. You can also use the following CLI commands to view all the threats and their associated default action. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; configure&lt;/P&gt;&lt;P&gt;# show predefined threats&amp;nbsp; ---&amp;gt; displays all the threats. Use forward slash followed by the threat ID to search for a specific threat ID (/36729)&lt;/P&gt;&lt;P&gt;# show predefined threats vulnerability &amp;lt;threatID&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may find &lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt; to also be helpful as it provides more information Click the magnifying icon to view the default action. &lt;/P&gt;&lt;P&gt;You can contact SE to place any feature requests. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Oct 2014 10:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18989#M13835</guid>
      <dc:creator>gchandrasekaran</dc:creator>
      <dc:date>2014-10-03T10:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18990#M13836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, seeing the default action is easy.&lt;/P&gt;&lt;P&gt;But seeing the current set action for certain signature (in specified profile) is impossible. You can only see in which rule it is included and then check the action for that rule. But I already had customers asking: "ok, show me that this signature is indeed in blocking mode for this profile".&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll open a feature request. And hopefully some of the readers here will help me with same requests &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 07:40:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18990#M13836</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-06T07:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18991#M13837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please share FR number so that we'll also vote for...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 07:53:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18991#M13837</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-10-06T07:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18992#M13838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmmm, another question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens if signature is included in multiple rules with different set actions? Does it work like security policy, top down and first rule that hits?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;rule that sets all critical signatures to default&lt;/P&gt;&lt;P&gt;rule which sets all signatures which have 'bash remote' to block.&lt;/P&gt;&lt;P&gt;What is the response now for signature ID &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;36729 which is 'critical' severity, includes words 'bash remote' and default action is alert?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In such case the ability to see signature response would come in handy &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 08:03:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18992#M13838</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-06T08:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18993#M13839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes; rules inside profile works from top to bottom.&lt;/P&gt;&lt;P&gt;for the example, it is alert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 08:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18993#M13839</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-10-06T08:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18994#M13840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanx! Good to know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 12:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18994#M13840</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-06T12:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18995#M13841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="5601" data-username="santonic" href="https://live.paloaltonetworks.com/people/santonic" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;santonic&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Rules inside vulnerability profile do not get checked from top to bottom. These rules are defined based on criteria's such as host type and severity.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;For example: Threat ID 36729 has following criteria's :&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Host type : Server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Severity : Critical &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;thus it matches the rule highlighted below:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;IMG alt="ertge.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16101_ertge.PNG" style="height: 383px; width: 620px;" /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;In this case, the action will be block for threat signature 36729.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;hshah has given a clear idea as to how the profile gets matched. It depends on which security rule the traffic matches and the profile attached to that rule.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hope this helps.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 21:55:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18995#M13841</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-06T21:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18996#M13842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="5601" data-username="santonic" href="https://live.paloaltonetworks.com/people/santonic" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;santonic&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;To add to the thread, the rules order in Vulnerability protection profile depends on the action field. For a given signature, the action taken is the most strict action match.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 01:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18996#M13842</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-07T01:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18997#M13843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I understand how security policy and security profiles work. I was just wondering about rules inside specific security profile in cases when one signature matches more than one rule.&lt;/P&gt;&lt;P&gt;So far I got 2 answers:&lt;/P&gt;&lt;P&gt;- rules inside security profile are matched from top to bottom&lt;/P&gt;&lt;P&gt;- action is set by the most strict rule for given signature&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone confirm which is correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 06:43:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18997#M13843</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-07T06:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18998#M13844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="5601" data-username="santonic" href="https://live.paloaltonetworks.com/people/santonic" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #779308; text-decoration: underline;"&gt;santonic&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;The &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;action is set by the most strict rule for given signature. This was confirmed by the product management team. &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 20:08:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18998#M13844</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-07T20:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18999#M13845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool, thanx for confirmation!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 06:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/18999#M13845</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-08T06:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - new signature's action set to default instead of the action specified in rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/19000#M13846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/10570"&gt;tshiv&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We did some testing and we found out that rule order does matter in IPS profile. So if a signature matches 2 rules, the action will be set by first rule it hits, matching the rules from top to bottom.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 14:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-new-signature-s-action-set-to-default-instead-of-the-action/m-p/19000#M13846</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-11-03T14:11:46Z</dc:date>
    </item>
  </channel>
</rss>

