<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent Scan in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-scan/m-p/22164#M16156</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello soporteseguridad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would configure reconnaissance protection via zone protection profile to protect your to detect and block host sweep , TCP and UDP scans.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, zone protection applies to incoming traffic. That means, if you want to protect DMZ&amp;nbsp; then you should apply zone-protection on the Untrust zone (facing Internet) and the Trust zone (&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;facing your LAN - if you wish to protect from inside threats as well ( for example an overtaken client is being used to DOS your DMZ devices))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some documents which will help is configuring it:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;Threat Prevention Deployment Tech Note&lt;/A&gt;&amp;nbsp; (Page 41-42)&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5078"&gt;Understanding DoS Protection&lt;/A&gt;(Page 10-11)&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6132"&gt;Zone Protection Profile not Engaging During Penetration Scan&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hope that helps!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Nov 2013 14:39:00 GMT</pubDate>
    <dc:creator>kadak</dc:creator>
    <dc:date>2013-11-11T14:39:00Z</dc:date>
    <item>
      <title>Prevent Scan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-scan/m-p/22163#M16155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;HI,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;we have&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;detected that we&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;are suffering&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;a scan of&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;all servers in&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;our &lt;/SPAN&gt;&lt;SPAN class="hps"&gt;DMZ&lt;/SPAN&gt;, &lt;SPAN class="hps"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;IP source&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;151.236.14.140&lt;/SPAN&gt;, &lt;SPAN class="hps"&gt;on port 443&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;How can we&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;avoid this kind of attack or prevent it?&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 13:35:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-scan/m-p/22163#M16155</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-11-11T13:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Scan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-scan/m-p/22164#M16156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello soporteseguridad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would configure reconnaissance protection via zone protection profile to protect your to detect and block host sweep , TCP and UDP scans.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, zone protection applies to incoming traffic. That means, if you want to protect DMZ&amp;nbsp; then you should apply zone-protection on the Untrust zone (facing Internet) and the Trust zone (&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;facing your LAN - if you wish to protect from inside threats as well ( for example an overtaken client is being used to DOS your DMZ devices))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some documents which will help is configuring it:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;Threat Prevention Deployment Tech Note&lt;/A&gt;&amp;nbsp; (Page 41-42)&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5078"&gt;Understanding DoS Protection&lt;/A&gt;(Page 10-11)&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6132"&gt;Zone Protection Profile not Engaging During Penetration Scan&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hope that helps!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 14:39:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-scan/m-p/22164#M16156</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-11T14:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Scan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-scan/m-p/22165#M16157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;soporteseguridad&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we know the source IP then there is no problem we can directly create a security rule sourcing the IP and destined to Dmz servers for all apps and ports.&lt;/P&gt;&lt;P&gt;We can further use Scan prevention in Zone protection profile and apply it to the right zones.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="zpp.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9706_zpp.PNG.png" style="width: 620px; height: 187px;" /&gt;&lt;/P&gt;&lt;P&gt;We can customize the action and change the interval and so on. Once set we can see the logs by running the command as indicated in below doc.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3103"&gt;How to Verify if Zone Protection is Working&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 15:58:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-scan/m-p/22165#M16157</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-11-11T15:58:25Z</dc:date>
    </item>
  </channel>
</rss>

