<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to REJECT instead of DROP? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30589#M22386</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; any news on this topic ? I would to see this implemented, I have some special conditions where it would help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Jul 2011 08:27:55 GMT</pubDate>
    <dc:creator>lardsa</dc:creator>
    <dc:date>2011-07-13T08:27:55Z</dc:date>
    <item>
      <title>How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30587#M22384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try as I might, I cannot find a way to do the equivalent of the venerable iptables target REJECT --with-icmp-ureachable or --with-tcp-reset for basic firewalling on a 4020.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is handy for bouncing internal clients quickly, whereas DROP is better to make things slower for adversaries who are scanning our nets from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example. If I want to prevent smtp/ntp/dns attempts for our internal clients, thus forcing them through the relevant internal services, I don't expect them to have to wait for a timeout, when a simple reject rule can speed things along for them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems the two targets available for basic layer 3 firewalling are simply allow, or drop. Why no reject?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope someone knows how. If this is the wrong forum I apologise, but I expect this is a missing feature. I feel it's quite a basic essential.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jul 2010 14:58:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30587#M22384</guid>
      <dc:creator>Priyan</dc:creator>
      <dc:date>2010-07-06T14:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30588#M22385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Priyan -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman","serif";}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d;"&gt;The deny action used in a security policy will either ‘drop’ or ‘drop-reset’ based on the app being used in the policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d;"&gt;For most browser-based apps, it is drop-reset - this prevents the browser from spinning while retrying.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d;"&gt;For client-server apps that are based on http (or other protocols that we have decoders for), we generally use drop-reset if the app is considered harmless.&lt;/SPAN&gt; We don't currently support icmp-host-unreachable for udp/icmp but it is on the cards.&lt;/P&gt;&lt;P class="MsoNormal"&gt;Srinivas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 20:16:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30588#M22385</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2010-07-13T20:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30589#M22386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; any news on this topic ? I would to see this implemented, I have some special conditions where it would help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 08:27:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30589#M22386</guid>
      <dc:creator>lardsa</dc:creator>
      <dc:date>2011-07-13T08:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30590#M22387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would also like the ability to select the type of drop manually.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 19:51:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30590#M22387</guid>
      <dc:creator>dlassalle</dc:creator>
      <dc:date>2012-02-07T19:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30591#M22388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We'd also like to select the type of deny. In some cases, we need to explicitity send RESET instead simply DROP the packet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 07:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30591#M22388</guid>
      <dc:creator>uniovi</dc:creator>
      <dc:date>2012-03-19T07:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30592#M22389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would also like to place myself in this feature-line regarding ability to (per security rule) define if the traffic should be denied (drop) or rejected (drop-reset). Perhaps it could be called just "deny" vs "deny-rst" in the gui.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would also be nice to be able to define if icmp-unreachable should be sent or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 07:51:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30592#M22389</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-19T07:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30593#M22390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also need the ability to select the type of drop manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"We don't currently support icmp-host-unreachable for udp/icmp but it is on the cards."&lt;/P&gt;&lt;P&gt;Any news about this feature ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 13:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30593#M22390</guid>
      <dc:creator>Duplem</dc:creator>
      <dc:date>2012-06-27T13:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30594#M22391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The same here...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is disastrous how much time I've spend on debugging timeouts...&lt;/P&gt;&lt;P&gt;tcp-reject from internal net to external/between zones is a must !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Pawel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 12:42:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30594#M22391</guid>
      <dc:creator>pawel_stankiewicz</dc:creator>
      <dc:date>2012-07-09T12:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30595#M22392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I second this.&amp;nbsp; This is a huge oversight on part of Palo Alto.&amp;nbsp; One neat feature of ScreenOS is the ability to specify RST on a per-zone basis...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 19:07:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30595#M22392</guid>
      <dc:creator>garryshtern</dc:creator>
      <dc:date>2012-07-30T19:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30596#M22393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mention that there is work in progress to provide further options for reject. I didn't see anything specific mentioned in the 6.0 release notes. Can you tell me whether there have been any improvements upon this?&amp;nbsp; We also require the ability to set a specific reject for a particular policy.&amp;nbsp; We'd like to let some things remain drop, but for specific subnets that we still want to block, we'd like to do a reject.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 00:26:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30596#M22393</guid>
      <dc:creator>Kevin.lane</dc:creator>
      <dc:date>2014-01-24T00:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30597#M22394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What happens when the drop rule has both application and service set to "any"? Drop or reject?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 18:10:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30597#M22394</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2014-01-24T18:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to REJECT instead of DROP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30598#M22395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any news about this topic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2014 09:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-reject-instead-of-drop/m-p/30598#M22395</guid>
      <dc:creator>vchanal</dc:creator>
      <dc:date>2014-08-06T09:02:11Z</dc:date>
    </item>
  </channel>
</rss>

