<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding Threat Exceptions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25563#M18650</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi EMr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your quick reply.&amp;nbsp;&amp;nbsp; We did install 5.0.4 but it appeared to cause problems with our internet connectivity (This is still being looked at by PA) so we reverted back to 4.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know where the exception is stored if I press the &lt;STRONG&gt;Add Threat Exception &lt;/STRONG&gt;button and whether it is possible to undo it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Apr 2013 11:16:05 GMT</pubDate>
    <dc:creator>phild</dc:creator>
    <dc:date>2013-04-16T11:16:05Z</dc:date>
    <item>
      <title>Adding Threat Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25561#M18648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp; I wonder if somebody can help me with a query?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running a 2050 as my firewall (I am new to looking after Palo Altos!).&amp;nbsp;&amp;nbsp; I have colleagues building workstations at another site coming across a VPN to access resources at my site.&amp;nbsp; The router and links are working fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One particular application is not getting through and is being blocked as a threat.&amp;nbsp; The entry in the log is: &lt;BR /&gt;&lt;STRONG&gt;SIP CSeq Header Field Integer Overflow&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ID:&amp;nbsp; 31788&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Severity: HIGH&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Several SIP based products are prone to an integer overflow while handling crafted requests containing invalid sequence numbers in CSeq header field. An attacker could exploit the vulnerability by sending a crafted request containing margin integer values in CSeq header. A successful exploit could lead to remote code execution or crash the server.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the option &lt;STRONG&gt;Add to Threat Exception &lt;/STRONG&gt;which I would like to press to see if it fixes my problem.&amp;nbsp; Before I press the button I would like to know where this exception is stored and how can I remove it if I want to reinclude it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Going forward can I create a policy which only allows it through if it is coming from s specific IP subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any questions then let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 10:49:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25561#M18648</guid>
      <dc:creator>phild</dc:creator>
      <dc:date>2013-04-16T10:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Threat Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25562#M18649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Phil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds PANOS 5.0 would be nice for you.&lt;/P&gt;&lt;P&gt;The detail of threat log looks as below on 5.0.4.&lt;/P&gt;&lt;P&gt;You can select profile and also you can use Exempt IP address (this is new from 5.0)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="WS000014.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6284_WS000014.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Emr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 11:09:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25562#M18649</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-04-16T11:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Threat Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25563#M18650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi EMr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your quick reply.&amp;nbsp;&amp;nbsp; We did install 5.0.4 but it appeared to cause problems with our internet connectivity (This is still being looked at by PA) so we reverted back to 4.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know where the exception is stored if I press the &lt;STRONG&gt;Add Threat Exception &lt;/STRONG&gt;button and whether it is possible to undo it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 11:16:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25563#M18650</guid>
      <dc:creator>phild</dc:creator>
      <dc:date>2013-04-16T11:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Threat Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25564#M18651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can choose profile even you run 4.1&lt;/P&gt;&lt;P&gt;The following doc might help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4080"&gt;How to Tune IPS in PAN-OS 4.1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This also might help you.&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3699" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Emr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 11:34:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25564#M18651</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-04-16T11:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Threat Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25565#M18652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to create a separate Vulnerability protection profile for the policy rules that you want to make exceptions for, as the exceptions are applied to the Vulnerability protection Profile. If you want it to be excepted from all rules, just except it from your generic Vulnerability protection profile. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 14:15:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-threat-exceptions/m-p/25565#M18652</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-04-16T14:15:56Z</dc:date>
    </item>
  </channel>
</rss>

