<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Antivirus Decoder Action in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34438#M25276</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mrsoldner,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to confirm couple of things.&lt;/P&gt;&lt;P&gt;- mrsoldner hitting Bug# 57763 &lt;/P&gt;&lt;P&gt;- workaround is to define explicit "alert" instead of "default(alert)" for WF Action&lt;/P&gt;&lt;P&gt;- permanent fix is in PanOS 5.0.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Oct 2014 15:39:38 GMT</pubDate>
    <dc:creator>dmaynard</dc:creator>
    <dc:date>2014-10-21T15:39:38Z</dc:date>
    <item>
      <title>Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34423#M25261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I feel silly asking this - wouldn't you want a deny on any decoder where a virus is detected rather than allowing the traffic and just throwing an alert?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 22:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34423#M25261</guid>
      <dc:creator>mrsoldner</dc:creator>
      <dc:date>2014-09-24T22:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34424#M25262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="21363" data-username="mrsoldner" href="https://live.paloaltonetworks.com/people/mrsoldner" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mrsoldner&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="padding: 0px 3px 0px 0px; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, action is taken based on the different severity level of that virus. If that virus is having &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;typically&lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; very little impact /or no impact on an organization's infrastructure. Then the action will be set to "alert".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 22:58:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34424#M25262</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T22:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34425#M25263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Setting a block for viruses on smtp will cause the originating server to keep trying to relay the email until a timeout occurs. This could potentially cause a lot of unwanted traffic pointed at your smtp server that is getting blocked over and over by the firewall. That may still be preferred to allowing a virus in via smtp, but it's just something to be aware of.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 23:06:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34425#M25263</guid>
      <dc:creator>jtyler</dc:creator>
      <dc:date>2014-09-24T23:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34426#M25264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1421" data-externalid="" data-presence="null" data-userid="26629" data-username="jtyler" href="https://live.paloaltonetworks.com/people/jtyler" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;jtyler&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a good example. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 23:17:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34426#M25264</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T23:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34427#M25265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there somewhere that Virus severity is noted?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 23:26:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34427#M25265</guid>
      <dc:creator>mrsoldner</dc:creator>
      <dc:date>2014-09-24T23:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34428#M25266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;jtyler wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Setting a block for viruses on smtp will cause the originating server to keep trying to relay the email until a timeout occurs. This could potentially cause a lot of unwanted traffic pointed at your smtp server that is getting blocked over and over by the firewall. That may still be preferred to allowing a virus in via smtp, but it's just something to be aware of.&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good point, I did some digging and found this:&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;Threat Prevention Deployment Tech Note&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like some intelligence is built in for SMTP and will send back a 541 response so that the other side doesn't keep resending the email.&amp;nbsp; POP and IMAP however don't have any intelligence built in.&amp;nbsp; So, per the doc:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;Note: The reason why SMTP, POP3 and IMAP have the default action set to ALERT is because in most cases there is &lt;/P&gt;
&lt;P&gt;already a dedicated Antivirus gateway solution in place for these protocols. Specifically for POP3 and IMAP, it is not &lt;/P&gt;
&lt;P&gt;possible to clean files or properly terminate an infected file-transfer in-stream without affecting the entire session. &lt;/P&gt;
&lt;P&gt;This is due to shortcomings in these protocols to deal with this kind of situation.&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&amp;nbsp; I think we'll stick with the defaults for now and &lt;EM&gt;potentially&lt;/EM&gt; ratchet up SMTP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 23:53:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34428#M25266</guid>
      <dc:creator>mrsoldner</dc:creator>
      <dc:date>2014-09-24T23:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34429#M25267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mrsoldner,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every virus signature has different severity. You can find that information from following link. Select type as a "virus".&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to feed either virus name or ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 00:25:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34429#M25267</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-25T00:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34430#M25268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;hshah wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hello Mrsoldner,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Every virus signature has different severity. You can find that information from following link. Select type as a "virus".&lt;/P&gt;
&lt;P&gt;&lt;A class="jive-link-external-small" href="https://threatvault.paloaltonetworks.com/" rel="nofollow"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to feed either virus name or ID.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Hardik Shah&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;A href="https://live.paloaltonetworks.com/u1/19490"&gt;hshah&lt;/A&gt; - I've never seen a severity included with a virus though which is why I'm puzzled.&amp;nbsp; For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ID: 3088393&lt;/P&gt;&lt;P&gt;The threat vault just calls it a virus.&amp;nbsp; It came in via SMTP (which by default, the action is alert) however in the logs it shows it was blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just making sure I fully understand.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 16:52:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34430#M25268</guid>
      <dc:creator>mrsold</dc:creator>
      <dc:date>2014-09-26T16:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34431#M25269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mrsold,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My bad, its vulnerability which has sev not anti-virus. Thanks for correcting me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 17:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34431#M25269</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-26T17:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34432#M25270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;HULK wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-link-profile-small" data-containerid="-1" data-containertype="-1" data-objectid="21363" data-objecttype="3" href="https://live.paloaltonetworks.com/people/mrsoldner"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mrsoldner&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="padding: 0px 3px 0px 0px; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As per my understanding, action is taken based on the different severity level of that virus. If that virus is having &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;typically&lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; very little impact /or no impact on an organization's infrastructure. Then the action will be set to "alert".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt; could you clarify?&amp;nbsp; My antivirus decoder for SMTP is set to "alert" for WildFire and Threat however I am seeing Virus blocks for SMTP traffic.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 17:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34432#M25270</guid>
      <dc:creator>mrsold</dc:creator>
      <dc:date>2014-09-26T17:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34433#M25271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you use alert profile but you see block logs ? that is interesting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 21:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34433#M25271</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-09-26T21:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34434#M25272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another reason the action may be set to alarm rather than deny as the default action is the possibility of false positives.&amp;nbsp; Palo Alto is pretty good about only setting drop/reset actions to signatures are have virtually no false positives.&amp;nbsp; You don't want to be blocking too many legitimate sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The alarm option then can give you a report on suspects that can be researched and confirmed.&amp;nbsp; If you subsequently find that virtually all the alarms are real then you have the option to change the action to a deny/reset instead of alarm.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Sep 2014 11:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34434#M25272</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-09-27T11:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34435#M25273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;panos wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;you use alert profile but you see block logs ? that is interesting.&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah,&amp;nbsp; very interesting indeed.&amp;nbsp; I need to do some more digging...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 12:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34435#M25273</guid>
      <dc:creator>mrsoldner</dc:creator>
      <dc:date>2014-09-29T12:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34436#M25274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah &lt;A href="https://live.paloaltonetworks.com/u1/12079"&gt;panos&lt;/A&gt; and &lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt; - Interesting indeed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="smtp.png" class="image-0 jive-image" height="208" src="https://live.paloaltonetworks.com/legacyfs/online/15849_smtp.png" style="height: 208px; width: 934.492753623189px;" width="934" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Av Profile:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="avprof.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15850_avprof.png" style="height: 410px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 13:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34436#M25274</guid>
      <dc:creator>mrsoldner</dc:creator>
      <dc:date>2014-09-29T13:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34437#M25275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, If i'm reading this right - the attachment was blocked but the email allowed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SS Threat.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15863_SS Threat.png" style="height: 146px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 22:25:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34437#M25275</guid>
      <dc:creator>mrsoldner</dc:creator>
      <dc:date>2014-09-29T22:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34438#M25276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mrsoldner,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to confirm couple of things.&lt;/P&gt;&lt;P&gt;- mrsoldner hitting Bug# 57763 &lt;/P&gt;&lt;P&gt;- workaround is to define explicit "alert" instead of "default(alert)" for WF Action&lt;/P&gt;&lt;P&gt;- permanent fix is in PanOS 5.0.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2014 15:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34438#M25276</guid>
      <dc:creator>dmaynard</dc:creator>
      <dc:date>2014-10-21T15:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus Decoder Action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34439#M25277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;Some more information on why default action is set to alert for POP3, IMAP and SMTP instead of block.&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;* &lt;STRONG&gt;POP3/IMAP&lt;/STRONG&gt; + block -&amp;gt; A virus mail will be blocked. BUT: You can not get a new email from this server until the virus email is deleted from the server. Because the whole POP3 session will be dropped each time you retry to retrieve you emails, since emails are not send separately with this protocol.&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;* &lt;STRONG&gt;SMTP&lt;/STRONG&gt; + block -&amp;gt; An SMTP 541 error message will be sent as part of the block action when a virus is detected. This will tell the mail server not to retry sending the message, allowing the firewall to drop the mail without the mail server trying to resend it. So I don't realy see why the default action would be just alert. I guess some smtp servers will not listen to these 541 error messages and keep resending the email...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Mar 2015 14:04:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-decoder-action/m-p/34439#M25277</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2015-03-31T14:04:23Z</dc:date>
    </item>
  </channel>
</rss>

