<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block page for vulnerability protection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31867#M23324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh yes sorry, was thinking of something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Vuln protection" in PAN is the IDP engine which acts at session-control level (just dropping the packets or sending tcp-rst's to make server and/or client to drop the connection).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current possible response pages seems to be (which you also can make your own versions of):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Default Antivirus Response Page&lt;/P&gt;&lt;P&gt;- Default Application Block Page&lt;/P&gt;&lt;P&gt;- Default File Blocking Block Page&lt;/P&gt;&lt;P&gt;- Default URL Filtering Response Page&lt;/P&gt;&lt;P&gt;- Default Anti-Spyware Download Response Page&lt;/P&gt;&lt;P&gt;- Default Decryption Opt-out Response Page&lt;/P&gt;&lt;P&gt;- Captive Portal Comfort Page&lt;/P&gt;&lt;P&gt;- URL Filtering Continue and Override Page&lt;/P&gt;&lt;P&gt;- SSL VPN Login Page&lt;/P&gt;&lt;P&gt;- SSL Certificate Revoked Notify Page&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Mar 2012 06:13:20 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-03-29T06:13:20Z</dc:date>
    <item>
      <title>Block page for vulnerability protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31864#M23321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been testing the security profile for vulnerability protection.&amp;nbsp; I set the action for all critical threats to block. What should I expect to see on the user computer screen if a site does contain a critical threat recognized by Palo Alto?&amp;nbsp; Should the user see a block page?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2012 21:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31864#M23321</guid>
      <dc:creator>oshcomp</dc:creator>
      <dc:date>2012-03-27T21:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Block page for vulnerability protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31865#M23322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the client is using a browser it should see the block page which informs the client of why access have been blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont forget to enable ssl-termination in order to inspect (and block) bad stuff using https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also make custom block pages if you wish (for example if you wish to use a different design/layout or for that matter use a local language).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the PA-4.1_Administrators_Guide.pdf for more info (search for "block page").&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2012 22:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31865#M23322</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-27T22:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block page for vulnerability protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31866#M23323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, the user would not see a block page for a vulnerability exploit that was detected. If a specially crafted web page contained an exploit, we would take the action associated with that signature on the profile, i.e. drop all packets and send a tcp reset to the client, server, or both, alert, etc. We don't have a block page for vulnerability protection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2012 23:49:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31866#M23323</guid>
      <dc:creator>fredallee</dc:creator>
      <dc:date>2012-03-28T23:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Block page for vulnerability protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31867#M23324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh yes sorry, was thinking of something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Vuln protection" in PAN is the IDP engine which acts at session-control level (just dropping the packets or sending tcp-rst's to make server and/or client to drop the connection).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current possible response pages seems to be (which you also can make your own versions of):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Default Antivirus Response Page&lt;/P&gt;&lt;P&gt;- Default Application Block Page&lt;/P&gt;&lt;P&gt;- Default File Blocking Block Page&lt;/P&gt;&lt;P&gt;- Default URL Filtering Response Page&lt;/P&gt;&lt;P&gt;- Default Anti-Spyware Download Response Page&lt;/P&gt;&lt;P&gt;- Default Decryption Opt-out Response Page&lt;/P&gt;&lt;P&gt;- Captive Portal Comfort Page&lt;/P&gt;&lt;P&gt;- URL Filtering Continue and Override Page&lt;/P&gt;&lt;P&gt;- SSL VPN Login Page&lt;/P&gt;&lt;P&gt;- SSL Certificate Revoked Notify Page&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 06:13:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-for-vulnerability-protection/m-p/31867#M23324</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-29T06:13:20Z</dc:date>
    </item>
  </channel>
</rss>

