<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Eicar Testvirus will not be recognized in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38615#M28286</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi tettema,&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;... Anything the firewall blocks should be blocked consistently. ..&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Hope so. But apparently this happens not in all cases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;If you are using a browser, it is possible that the browser is caching data and reserving it to you.&amp;nbsp; &lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;I used a browser, but the "pdf"-file was surely not in the browsercache.&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;Are you using a block action or a continue action in your AV profile?&amp;nbsp; Which ones specifically are you seeing this behavior with, and can you describe the sequence of actions in detail?&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Please take a look at our AV-profile. There is no "continue". &lt;/P&gt;&lt;P&gt;&lt;IMG alt="av1.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3775_av1.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Sorry, there is no more detail. I simply clicking on the pdf link&amp;nbsp; &lt;A href="http://www.faerber.fidelitas.de/virtst/eicar.pdf" title="http://www.faerber.fidelitas.de/virtst/eicar.pdf"&gt;http://www.faerber.fidelitas.de/virtst/eicar.pdf&lt;/A&gt; and see sometimes my firewall warning "blocking a dangerous site", and some other times "Fehler beim Laden des PDF-Dokumentes" (english translation: "Error while loading the PDF file"), because it is not really a pdf file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Aug 2012 20:31:27 GMT</pubDate>
    <dc:creator>mhuels</dc:creator>
    <dc:date>2012-08-14T20:31:27Z</dc:date>
    <item>
      <title>Eicar Testvirus will not be recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38613#M28284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the website &lt;A href="http://www.faerber.fidelitas.de/eicar1.htm" title="http://www.faerber.fidelitas.de/eicar1.htm"&gt; EICAT TESTVIRUS &lt;/A&gt;resides a lot of different kinds of eicar. Most of them will not be recognized by the Palo Alto Networks AV-Engine. The behaviour of the firewall is thereby a bit confusing. It seems: if you click on the links more then one time, you can download the virus on the second or third instance. Especially the PDF-Eicar often downloads on the second click.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are driving PAN OS 4.0.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greets&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 15:08:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38613#M28284</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2012-08-14T15:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar Testvirus will not be recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38614#M28285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manfred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to understand the test setup a little more.&amp;nbsp; Anything the firewall blocks should be blocked consistently.&amp;nbsp; If you are using a browser, it is possible that the browser is caching data and reserving it to you.&amp;nbsp; Are you using a block action or a continue action in your AV profile?&amp;nbsp; Which ones specifically are you seeing this behavior with, and can you describe the sequence of actions in detail?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 20:11:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38614#M28285</guid>
      <dc:creator>tettema</dc:creator>
      <dc:date>2012-08-14T20:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar Testvirus will not be recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38615#M28286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi tettema,&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;... Anything the firewall blocks should be blocked consistently. ..&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Hope so. But apparently this happens not in all cases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;If you are using a browser, it is possible that the browser is caching data and reserving it to you.&amp;nbsp; &lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;I used a browser, but the "pdf"-file was surely not in the browsercache.&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;Are you using a block action or a continue action in your AV profile?&amp;nbsp; Which ones specifically are you seeing this behavior with, and can you describe the sequence of actions in detail?&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Please take a look at our AV-profile. There is no "continue". &lt;/P&gt;&lt;P&gt;&lt;IMG alt="av1.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3775_av1.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Sorry, there is no more detail. I simply clicking on the pdf link&amp;nbsp; &lt;A href="http://www.faerber.fidelitas.de/virtst/eicar.pdf" title="http://www.faerber.fidelitas.de/virtst/eicar.pdf"&gt;http://www.faerber.fidelitas.de/virtst/eicar.pdf&lt;/A&gt; and see sometimes my firewall warning "blocking a dangerous site", and some other times "Fehler beim Laden des PDF-Dokumentes" (english translation: "Error while loading the PDF file"), because it is not really a pdf file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 20:31:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38615#M28286</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2012-08-14T20:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar Testvirus will not be recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38616#M28287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manfred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried that link on one of our PAN 500 running version: 4.0.3&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="dashboard" id="TableGeneralInformation" width="340"&gt;&lt;TBODY id="BodyGeneralInformation"&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_align_right"&gt;Application version&lt;/TD&gt;&lt;TD align="left" class="dashboard"&gt;319-1453 (2012/07/17)&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate_align_right"&gt;Threat version&lt;/TD&gt;&lt;TD align="left" class="dashboard_alternate"&gt;319-1453 (2012/07/17)&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_align_right"&gt;Antivirus version&lt;/TD&gt;&lt;TD align="left" class="dashboard"&gt;812-1116 (2012/08/09)&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate_align_right"&gt;URL Filtering version&lt;/TD&gt;&lt;TD align="left" class="dashboard_alternate"&gt;3922&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;And it's working fine every time, have you setup any custom warning pages or are they out of the box default? Looks like a bug to me if the config is 100%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tested config is running a very simple rulebase (small) and it's only using below throughput and CPU/Mem at the time of testing. The segment if going through a VWire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MGM CPU: 7%&lt;/P&gt;&lt;P&gt;Data Plane CPU: 5%&lt;BR /&gt;Device is up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 139 days 11 hours 20 mins 52 sec&lt;/P&gt;&lt;P&gt;Packet rate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 295/s&lt;/P&gt;&lt;P&gt;Throughput&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1434 Kbps&lt;/P&gt;&lt;P&gt;Total active sessions : 358&lt;/P&gt;&lt;P&gt;Active TCP sessions&amp;nbsp;&amp;nbsp; : 323&lt;/P&gt;&lt;P&gt;Active UDP sessions&amp;nbsp;&amp;nbsp; : 35&lt;/P&gt;&lt;P&gt;Active ICMP sessions&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Out of interest is this blocked on the way back from the download point or when the client tries to access the pdf?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2012 07:31:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38616#M28287</guid>
      <dc:creator>Ante</dc:creator>
      <dc:date>2012-08-15T07:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar Testvirus will not be recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38617#M28288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sec sec,&lt;/P&gt;&lt;P&gt;our working firewall is a bit more used&lt;/P&gt;&lt;P&gt;Device is up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0 day 13 hours 47 mins 18 sec&lt;/P&gt;&lt;P&gt;Packet rate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 4144/s&lt;/P&gt;&lt;P&gt;Throughput&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 20701 Kbps&lt;/P&gt;&lt;P&gt;Total active sessions : 7915&lt;/P&gt;&lt;P&gt;Active TCP sessions&amp;nbsp;&amp;nbsp; : 7104&lt;/P&gt;&lt;P&gt;Active UDP sessions&amp;nbsp;&amp;nbsp; : 781&lt;/P&gt;&lt;P&gt;Active ICMP sessions&amp;nbsp; : 16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our block page is customized, but in a very simple way. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect that there is a performance problem by blocking "dangerous" content. If the firewall dont has the time to block the first bytes, it will block in the course of the http session (which could be build by more than one tcp sessions). And so, a small part of the pdf file will reach the client, leading to an error message of the browser plugin. Assuming that the firewall cannot buffer a lot of bytes, it seems to be possible that the firewall recognize dangerous content after starting to deliver the content. But then it would be imho more correct to sending the block page instead of simply blocking the further content.&lt;/P&gt;&lt;P&gt;Anyway, since we upgraded to 4.1.7, the problem seems to be mitigated or dead. I will continue with testing during the next days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2012 09:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38617#M28288</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2012-08-15T09:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar Testvirus will not be recognized</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38618#M28289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have noticed the same behaviour on 2050 and older PANOS (pre 4.1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes the bad packet was let through with a following rst which depending on browser could mean that the browser would render whatever it got so far (internet explorer did this of course &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you should verify so you have ssl termination activated otherwise the https downloads will bypass your PA's AV/IPS functions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2012 22:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-testvirus-will-not-be-recognized/m-p/38618#M28289</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-20T22:58:56Z</dc:date>
    </item>
  </channel>
</rss>

