<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: is it safe to raise &amp;quot;action&amp;quot; to block? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31605#M23109</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes for brute force attack we can have time based block ip as action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to object -&amp;gt; Vul profiles -&amp;gt; choose custom and click on the small "pencil" icon of the brute force sig to configure it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Sep 2011 06:37:39 GMT</pubDate>
    <dc:creator>jleung</dc:creator>
    <dc:date>2011-09-20T06:37:39Z</dc:date>
    <item>
      <title>is it safe to raise "action" to block?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31598#M23102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i noticed that in some "critical", "high" and "medium" severity vulnerabilities, the default action is just "alert"... especially those brute-force attempts. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the moment, our system is set for default to take care of these.&amp;nbsp; however, i remember a thread here advising to set the action to "block" for medium severity on the server side vulnerabilities...&amp;nbsp; is it safe to set action to "block" for "critical", "high" and "medium" severity for server side?&amp;nbsp; will this break applications?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- ron &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 00:56:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31598#M23102</guid>
      <dc:creator>RonaldGo</dc:creator>
      <dc:date>2011-06-17T00:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: is it safe to raise "action" to block?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31599#M23103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Ronaldgoh wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i noticed that in some "critical", "high" and "medium" severity vulnerabilities, the default action is just "alert"... especially those brute-force attempts. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the moment, our system is set for default to take care of these.&amp;nbsp; however, i remember a thread here advising to set the action to "block" for medium severity on the server side vulnerabilities...&amp;nbsp; is it safe to set action to "block" for "critical", "high" and "medium" severity for server side?&amp;nbsp; will this break applications?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- ron &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you raise your level to "block" and the threat is detected the firewall will, as the name suggests, block the traffic from transitting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, if you're 100% sure the threats being detected are valid, then I suggest you might want to block them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If, however, you're worried about false positives - then don't. The block action may well break soemthing, especially if it triggers a positive threat detection when it's not really a threat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Alert" is good if you have time to sit and watch threat logs, and can get on top of reported threats immediately - if you're like msot people and DON'T have this time, then block is a good option. Depends how paranoid you are, and how critical potentially blocking a valid action might be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 05:07:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31599#M23103</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-06-17T05:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: is it safe to raise "action" to block?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31600#M23104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;If you raise your level to "block" and the threat is detected the&amp;nbsp; firewall will, as the name suggests, block the traffic from transitting.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Now, if you're 100% sure the threats being detected are valid, then I suggest you might want to block them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;If,&amp;nbsp; however, you're worried about false positives - then don't. The block&amp;nbsp; action may well break soemthing, especially if it triggers a positive&amp;nbsp; threat detection when it's not really a threat.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;"Alert"&amp;nbsp; is good if you have time to sit and watch threat logs, and can get on&amp;nbsp; top of reported threats immediately - if you're like msot people and&amp;nbsp; DON'T have this time, then block is a good option. Depends how paranoid&amp;nbsp; you are, and how critical potentially blocking a valid action might be.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi! I just checked and it doesn`t seem to be possible to export this list of vulnerabilities and default actions when you go &lt;STRONG&gt;Objects&lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Antivirus&lt;/STRONG&gt;, &lt;STRONG&gt;Anti-spyware&lt;/STRONG&gt; and &lt;STRONG&gt;Vulnerability&lt;/STRONG&gt; &lt;STRONG&gt;Protection&lt;/STRONG&gt; and then choose New - Custom.&lt;/P&gt;&lt;P&gt;Where is the list available in printable format?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your quick answer would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 14:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31600#M23104</guid>
      <dc:creator>itchelpdesk</dc:creator>
      <dc:date>2011-09-16T14:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: is it safe to raise "action" to block?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31601#M23105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 4.0 you can view all the signatures along with their default actions by creating or opening a profile, and clicking "custom".&amp;nbsp; From there you can page through all the signatures and see their default actions.&amp;nbsp; Similarly, in 4.1, you'll have the same capability in the Exceptions tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While this can get you the data you're looking for, it is still page-by-page, and not readily printable.&amp;nbsp; However, we do have a feature coming down the pipeline that will allow you to perform a CSV export of all signatures in a given profile.&amp;nbsp; You will be able to use this feature with a wildcare profile to get the report you're looking for.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 22:26:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31601#M23105</guid>
      <dc:creator>tettema</dc:creator>
      <dc:date>2011-09-16T22:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: is it safe to raise "action" to block?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31602#M23106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, there are some companies which prefer to have very strict security and they will choose block as the action. On the other hand if service availablity is much more important you better choose medium and review specific sig on and off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Sep 2011 07:41:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31602#M23106</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-17T07:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: is it safe to raise "action" to block?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31603#M23107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;SPAN style="font-size: 8pt;"&gt;While this can get you the data you're looking for, it is still &lt;BR /&gt;page-by-page, and not readily printable.&amp;nbsp; However, we do have a feature &lt;BR /&gt;coming down the pipeline that will allow you to perform a CSV export of &lt;BR /&gt;all signatures in a given profile.&amp;nbsp; You will be able to use this feature &lt;BR /&gt;with a wildcare profile to get the report you're looking for.&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please advise in which version the feature will be enabled to export the vulnerability information in CSV?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2011 08:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31603#M23107</guid>
      <dc:creator>itchelpdesk</dc:creator>
      <dc:date>2011-09-19T08:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: is it safe to raise "action" to block?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31604#M23108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've raised action to block for a lot of the brute-force attacks... and the status on the monitor shows "drop-all-packets"... but the attacks kept continuing...&amp;nbsp; is there a setting to stop the connection for 10 minutes or more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;even though the packets are dropped (according to PA monitor), thje attackers seem to just continue with the brute force attacks on our systems...&amp;nbsp; it's quite irritating and i suspect eventually they might be able to get through...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wish PA can change the way it responds to brute force threats...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- ron &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Sep 2011 06:01:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31604#M23108</guid>
      <dc:creator>RonaldGo</dc:creator>
      <dc:date>2011-09-20T06:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: is it safe to raise "action" to block?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31605#M23109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes for brute force attack we can have time based block ip as action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to object -&amp;gt; Vul profiles -&amp;gt; choose custom and click on the small "pencil" icon of the brute force sig to configure it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Sep 2011 06:37:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-safe-to-raise-quot-action-quot-to-block/m-p/31605#M23109</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-20T06:37:39Z</dc:date>
    </item>
  </channel>
</rss>

