<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Still no way to set SPECIFIC threat exceptions??? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20205#M14700</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...The traffic log is recording traffic events while the threat log is recording threat events.&amp;nbsp; If there is traffic (regardless if the threat is present or not) then it is recorded in the traffic log.&amp;nbsp; You are viewing the traffic log hence you're seeing the traffic activity.&amp;nbsp; The threat log should not register the event with threat ID 12345 because it is being ingored.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about changing the rule name from "Ignore ID 12345" to ""Scan all, Ignore ID 12345"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Feb 2012 22:46:04 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-02-09T22:46:04Z</dc:date>
    <item>
      <title>Still no way to set SPECIFIC threat exceptions???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20202#M14697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I created this thread over a year ago...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/message/3636#3636"&gt;https://live.paloaltonetworks.com/message/3636#3636&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...is there still no more intuitive way to be more granular when it comes to creating threat exceptions? I'm still having the same problem I report at the bottom of that thread.&amp;nbsp; For example...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to create a rule to ignore Threat ID 12345.&amp;nbsp; If I use these rule settings...&lt;/P&gt;&lt;P&gt;Rule Name = Exception-12345&lt;/P&gt;&lt;P&gt;Source = Internal Address Space&lt;/P&gt;&lt;P&gt;Destination = Any&lt;/P&gt;&lt;P&gt;Application = web-browsing&lt;/P&gt;&lt;P&gt;Service = service-http&lt;/P&gt;&lt;P&gt;Profile = Vulnerability profile with exception for Threat ID 12345&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...then it would successfully ignore threat 12345, but ANYTHING else that meets these rule requirements(even if it has nothing to do with Threat ID 12345)will be logged as this rule(Exception-12345) in the traffic log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 15:08:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20202#M14697</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2012-02-09T15:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Still no way to set SPECIFIC threat exceptions???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20203#M14698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which answer did the sales rep return to you regarding this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean that it will be logged in the traffic log?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You didnt setup a log entry for this rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then if you use default for the other threats then its depends on how each threat is setup in the threat db if it should just alert (just log) or deny (block and log). Given that you get a hit for the other threats that is...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 16:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20203#M14698</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-09T16:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Still no way to set SPECIFIC threat exceptions???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20204#M14699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To simplify my question...Is there a way to create Threat Exceptions for a specific source and/or destination IP?&amp;nbsp; Currently, the only way to create an Exception is to completely ignore the threat.&amp;nbsp; No matter what source or destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I am able to create a rule in the Security Policy called "Ignore ID 12345".&amp;nbsp; The rule has this settings, traffic from source 192.168.1.10 going to destination ANY, using Application "web-browsing", and using a Vulnerability Profile that has an Exception for Threat ID 12345.&lt;/P&gt;&lt;P&gt;This rule will not log any Threats with ID 12345 if it's coming from 192.168.1.10 going on ANY, using "web-browsing".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem, ANY OTHER traffic coming from 192.168.1.10 going to ANY, using "web-browsing" will show up in the Traffic Log as using rule "Ignore ID 12345", even if it has nothing to do with the Threat ID 12345.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 21:37:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20204#M14699</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2012-02-09T21:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Still no way to set SPECIFIC threat exceptions???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20205#M14700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...The traffic log is recording traffic events while the threat log is recording threat events.&amp;nbsp; If there is traffic (regardless if the threat is present or not) then it is recorded in the traffic log.&amp;nbsp; You are viewing the traffic log hence you're seeing the traffic activity.&amp;nbsp; The threat log should not register the event with threat ID 12345 because it is being ingored.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about changing the rule name from "Ignore ID 12345" to ""Scan all, Ignore ID 12345"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 22:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20205#M14700</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-09T22:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Still no way to set SPECIFIC threat exceptions???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20206#M14701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create a custom threatpolicy (that you can group with other custom or default settings into a profile group).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This custom threatpolicy (or the whole profile group) can then be applied for your traffic to/from a specific ip-address or such.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the ruleset in PAN is top-down first-match you can set it up as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule1: srcip=x.x.x.x, threatprofile=ALL_BUT_12345&lt;BR /&gt;rule2: srcip=any, threatprofile=default&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 07:57:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/still-no-way-to-set-specific-threat-exceptions/m-p/20206#M14701</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-10T07:57:28Z</dc:date>
    </item>
  </channel>
</rss>

