<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone Protection /Host Sweep settings... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-host-sweep-settings/m-p/200#M162</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please visit this link:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3972"&gt;https://live.paloaltonetworks.com/docs/DOC-3972&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Jun 2014 09:53:21 GMT</pubDate>
    <dc:creator>winwan</dc:creator>
    <dc:date>2014-06-30T09:53:21Z</dc:date>
    <item>
      <title>Zone Protection /Host Sweep settings...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-host-sweep-settings/m-p/199#M161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN" style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN" style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;I tried to adjust the "Host sweep," according to my network traffic, but I don`t get the results that want:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Inteval (sec)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ?&lt;/P&gt;&lt;P&gt;Threshold (events)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="hps"&gt;&lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Example: Given these &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="hps"&gt;&lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;threats&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;&lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/13726_pastedImage_2.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made the following query to see the number of events in 10 seconds: &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: courier new,courier;"&gt;( addr.src in 172.16.29.&lt;SPAN style="color: #c00000;"&gt;111 &lt;/SPAN&gt;) and ( port.dst eq 161 ) and ( receive_time geq '2014/06/02 11:56:00' ) and ( receive_time leq '2014/06/02 11:56:10' )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/13733_pastedImage_7.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;Result&lt;/SPAN&gt;&lt;SPAN class="shorttext"&gt;: &lt;/SPAN&gt; &lt;SPAN class="hps"&gt;1354&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;events&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;in&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;10 seconds.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;it does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;I have also tried adding exceptions, but does not work, this not stop to generate threat :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;&lt;IMG alt="" class="image-2 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/13734_pastedImage_21.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is internal traffic and generated me threat "SCAN: Host Sweep" :&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/13735_pastedImage_27.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;don´t know if&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;I'm doing well&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;or not?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;Could&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;anyone help me?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dicu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2014 10:27:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-host-sweep-settings/m-p/199#M161</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-06-02T10:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection /Host Sweep settings...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-host-sweep-settings/m-p/200#M162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please visit this link:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3972"&gt;https://live.paloaltonetworks.com/docs/DOC-3972&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 09:53:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-host-sweep-settings/m-p/200#M162</guid>
      <dc:creator>winwan</dc:creator>
      <dc:date>2014-06-30T09:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection /Host Sweep settings...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-host-sweep-settings/m-p/201#M163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That IP exception is for user identification not for Zone Protection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jan 2015 01:46:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-host-sweep-settings/m-p/201#M163</guid>
      <dc:creator>ddharmalingam</dc:creator>
      <dc:date>2015-01-10T01:46:05Z</dc:date>
    </item>
  </channel>
</rss>

