<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How  to block the real IPs from CDN? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2627#M1959</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are they embedding the IP address in the TCP option 28 header or HTTP 'x-forwarded-for' header or another header?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are using&amp;nbsp; the TCP option 28 header, I suggest you contact your local Palo Alto Nwks' SE and submit a feature request.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are using the HTTP 'x-forwarded-for' header, the PA can log the header so you can correlate the logs to determine the real IP of the intruder.&amp;nbsp; From there, you can write a custom threat signature to match the real IP and block this new custom threat. This is a manual process though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Jan 2014 16:44:53 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2014-01-27T16:44:53Z</dc:date>
    <item>
      <title>How  to block the real IPs from CDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2624#M1956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any function that can makes the PA block the traffic of the real IP instead of CDN IPs?&lt;/P&gt;&lt;P&gt;We deployed the PA NGFW on the external side of our web server and enabled the Threat Prevention function. Because we are using the CDN, so from the web server, all the source IPs in the traffic are hosted by the CDN service provider.&lt;/P&gt;&lt;P&gt;So when the PA&amp;nbsp; NGFW blocks&amp;nbsp; the source IP addresses because of the attack behavior, is there any way to block the real IPs of the attackers nor the IPs hosted by the CDN provider?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Jan 2014 04:55:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2624#M1956</guid>
      <dc:creator>SteveY</dc:creator>
      <dc:date>2014-01-26T04:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: How  to block the real IPs from CDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2625#M1957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Do you know if the CDN provider is passing the real IP address in any way to your web server such that the PA can see it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 15:34:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2625#M1957</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2014-01-27T15:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: How  to block the real IPs from CDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2626#M1958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for reply, rmonvon.&lt;/P&gt;&lt;P&gt;Yes, we have asked our CDN provider to pass the real IP addresses in the packet header.&lt;/P&gt;&lt;P&gt;Do you have any idea?&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 15:55:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2626#M1958</guid>
      <dc:creator>SteveY</dc:creator>
      <dc:date>2014-01-27T15:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: How  to block the real IPs from CDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2627#M1959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are they embedding the IP address in the TCP option 28 header or HTTP 'x-forwarded-for' header or another header?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are using&amp;nbsp; the TCP option 28 header, I suggest you contact your local Palo Alto Nwks' SE and submit a feature request.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are using the HTTP 'x-forwarded-for' header, the PA can log the header so you can correlate the logs to determine the real IP of the intruder.&amp;nbsp; From there, you can write a custom threat signature to match the real IP and block this new custom threat. This is a manual process though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 16:44:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2627#M1959</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2014-01-27T16:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: How  to block the real IPs from CDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2628#M1960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;They are embedding the IP address in the HTTP 'x-forwarded-for' header.&lt;/P&gt;&lt;P&gt;Can the blocking function be automatical?&lt;/P&gt;&lt;P&gt;For example, if the attacker is launching a DOS attack, can PA only block or quarantine the real IP nor the CDN IP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 17:43:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2628#M1960</guid>
      <dc:creator>SteveY</dc:creator>
      <dc:date>2014-01-27T17:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: How  to block the real IPs from CDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2629#M1961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For example, if I enable syn flood prevetion, will the PA FW quarantine the real IPs or CDN IP? Thank you!&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11332_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 17:58:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2629#M1961</guid>
      <dc:creator>SteveY</dc:creator>
      <dc:date>2014-01-27T17:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: How  to block the real IPs from CDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2630#M1962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The default behavior of the PA will take action on the source IP address, and in this case this would be the CDN's IP address.&amp;nbsp;&amp;nbsp; At this time, the PA cannot take action on the &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;IP address in the HTTP 'x-forwarded-for' header.&lt;/SPAN&gt;&amp;nbsp; Please contact &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;your local Palo Alto Nwks' SE and submit a feature request.&amp;nbsp; You can turn on logging for&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; HTTP 'x-forwarded-for' header:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1128"&gt;Enabling support for the  X-Forwarded-For HTTP header&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 18:17:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-the-real-ips-from-cdn/m-p/2630#M1962</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2014-01-27T18:17:22Z</dc:date>
    </item>
  </channel>
</rss>

