<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inconsistent documentation on zone protection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26243#M19160</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/29784"&gt;rvandegrift&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to Zone protection, statement number 2 is accurate. That is, it is applied to specific zones regardless of number of interfaces associated with it. And for this purpose, there is only single counter. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Separate counter mentioned in statement 1 is for Reconnaissance Protection, which will maintain counter for all different attempts made to sniff the traffic. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Nov 2014 16:32:04 GMT</pubDate>
    <dc:creator>ssharma</dc:creator>
    <dc:date>2014-11-04T16:32:04Z</dc:date>
    <item>
      <title>Inconsistent documentation on zone protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26242#M19159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Palo Alto's documentation is inconsistent on the behavior of flood protection when it is applied by a zone protection policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) "Threat Prevention Deployment Tech Note - Version 2.0 RevA", page 44 says that the zone protection based flood protection applies per source-destination-port tuple:&lt;/P&gt;&lt;P&gt;"Configure Flood Protection settings based on the number of packets you want to allow to each service behind the firewall. Settings apply to all traffic that enters the network through any interface in the zone on which the Zone Protection Profile is active, but a separate counter is maintained for each source IP/destination IP/destination port tuple."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) "Threat Prevention Deployment Tech Note - Version 2.0 RevA", page 45 directly contradicts this:&lt;/P&gt;&lt;P&gt;"Flood Protection enabled under Zone Protection is applied to the aggregate traffic seen on a specific zone. It will maintain a single counter for all traffic, regardless of source IP/destination IP/destination port."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which is correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 16:16:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26242#M19159</guid>
      <dc:creator>rvandegrift</dc:creator>
      <dc:date>2014-11-04T16:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent documentation on zone protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26243#M19160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/29784"&gt;rvandegrift&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to Zone protection, statement number 2 is accurate. That is, it is applied to specific zones regardless of number of interfaces associated with it. And for this purpose, there is only single counter. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Separate counter mentioned in statement 1 is for Reconnaissance Protection, which will maintain counter for all different attempts made to sniff the traffic. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 16:32:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26243#M19160</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-04T16:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent documentation on zone protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26244#M19161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What makes you think that the first comment applies to reconnaissance protection?&amp;nbsp; The quote above is from the flood protection section.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 16:34:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26244#M19161</guid>
      <dc:creator>rvandegrift</dc:creator>
      <dc:date>2014-11-04T16:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent documentation on zone protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26245#M19162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the comment is from Flood Protection, but the statement "separate counter is maintained for each source IP/destination IP/destination port tuple", makes sense with reconnaissance protection as attacker will try to sniffs various ports on same destination or different ports on different destinations. Where as in flood, attacker will flood the network mostly to a known or single ip rendering it useless to process other legitimate request. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 16:40:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inconsistent-documentation-on-zone-protection/m-p/26245#M19162</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-04T16:40:45Z</dc:date>
    </item>
  </channel>
</rss>

