<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Malware Site blocking: 94.102.55.20 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/malware-site-blocking-94-102-55-20/m-p/25717#M18745</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello forum, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am seeing traffic to a particular IP address from one computer that I know has been infected with a virus (we're busy getting rid of it). The connection is SSL and we are about to implement SSL decryption on our Palo, just not this second. The hoster of the IP address is Ecatel who are synonymous with with malwares. We have a valid license for threat, url, av which is uptodate on the box. I am wondering why it's not being blocked as dangerous even though our security profiles are basically set to block for anything 'medium' and higher. Because it's SSL it's not being categorised which isn't helpful - is that the reason why it's not being stopped? Brightcloud list it as unsafe. Any ideas of how to get a block on this that is more dynamic than just that one IP address (that might change) would be great. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination is 94.102.55.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can post more info if you need, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;NC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Oct 2012 11:06:21 GMT</pubDate>
    <dc:creator>Conde01</dc:creator>
    <dc:date>2012-10-04T11:06:21Z</dc:date>
    <item>
      <title>Malware Site blocking: 94.102.55.20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware-site-blocking-94-102-55-20/m-p/25717#M18745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello forum, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am seeing traffic to a particular IP address from one computer that I know has been infected with a virus (we're busy getting rid of it). The connection is SSL and we are about to implement SSL decryption on our Palo, just not this second. The hoster of the IP address is Ecatel who are synonymous with with malwares. We have a valid license for threat, url, av which is uptodate on the box. I am wondering why it's not being blocked as dangerous even though our security profiles are basically set to block for anything 'medium' and higher. Because it's SSL it's not being categorised which isn't helpful - is that the reason why it's not being stopped? Brightcloud list it as unsafe. Any ideas of how to get a block on this that is more dynamic than just that one IP address (that might change) would be great. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination is 94.102.55.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can post more info if you need, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;NC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 11:06:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware-site-blocking-94-102-55-20/m-p/25717#M18745</guid>
      <dc:creator>Conde01</dc:creator>
      <dc:date>2012-10-04T11:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Site blocking: 94.102.55.20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware-site-blocking-94-102-55-20/m-p/25718#M18746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi NC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;If you think the firewall did not capture a valid threat, you can submit a pcap from the client PC and the related traffic logs by opening a support ticket and we can hand it over to threat team for validation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Also in the ticket description if you can give a brief description of threat.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Here is the document on how you to collect the data&amp;nbsp; ( threat log details collection in the doc below would not apply in your case)&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2769"&gt;https://live.paloaltonetworks.com/docs/DOC-2769&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 18:20:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware-site-blocking-94-102-55-20/m-p/25718#M18746</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-04T18:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Site blocking: 94.102.55.20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware-site-blocking-94-102-55-20/m-p/25719#M18747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You said that this is an SSL site. How are you trying to block this ? Are you using URL filtering to block malware-sites category ? If that is the case then we should be blocking it based on the SSL certificate common name. I also see that you are using the antivirus profiles to block this virus then you have to go for SSL decryption option. Please share some information on what is the website URL, how you are trying to block this (Antivirus or URL filtering). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 19:06:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware-site-blocking-94-102-55-20/m-p/25719#M18747</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-10-04T19:06:30Z</dc:date>
    </item>
  </channel>
</rss>

