<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vulnerability Protection - BlockIP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31455#M23015</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have configured a vulnerability protection profile to blacklist the ip addresses of attackers for all brute force login attempts with the signatures provided in the threat database.&amp;nbsp; The profile works very well.&amp;nbsp; However, i would now like to see the list of currently blacklisted ip addresses. I know it only blacklists for up to an hour, but there has to be a command to show the current ip addresses on the blacklist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone knows it, please assist me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 May 2012 14:22:09 GMT</pubDate>
    <dc:creator>1stalliance</dc:creator>
    <dc:date>2012-05-10T14:22:09Z</dc:date>
    <item>
      <title>Vulnerability Protection - BlockIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31455#M23015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have configured a vulnerability protection profile to blacklist the ip addresses of attackers for all brute force login attempts with the signatures provided in the threat database.&amp;nbsp; The profile works very well.&amp;nbsp; However, i would now like to see the list of currently blacklisted ip addresses. I know it only blacklists for up to an hour, but there has to be a command to show the current ip addresses on the blacklist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone knows it, please assist me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 14:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31455#M23015</guid>
      <dc:creator>1stalliance</dc:creator>
      <dc:date>2012-05-10T14:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Protection - BlockIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31456#M23016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't found a command just yet, but you should be able to goto the threat logs in the webUI, create an action filter that equals "block-ip" and run the filter in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should show you what IPs are getting blocked and when. On a side note, for this to be more real-time, you may want to enable logging at the start of the session for the rule that's logging your block-ip threats.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 May 2012 18:32:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31456#M23016</guid>
      <dc:creator>jseals</dc:creator>
      <dc:date>2012-05-13T18:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Protection - BlockIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31457#M23017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shouldnt "log on session end" be equal as "log on session start" in this case since the ip is being blocked and hence the session is ended by the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean comparing with last "deny &amp;amp; log" rule in the bottom of your ruleset. Since the session its denied it shouldnt matter if you select "log on session start" or "log on session end".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 07:10:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31457#M23017</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-14T07:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Protection - BlockIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31458#M23018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug dataplane show dos&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; block-table&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 15:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-blockip/m-p/31458#M23018</guid>
      <dc:creator>Fujitsu_cyberSOC</dc:creator>
      <dc:date>2012-05-14T15:35:46Z</dc:date>
    </item>
  </channel>
</rss>

