<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Except Specific IPs from port scan detection / Zone Protection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41371#M30404</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see a way to create an exception for one IP-Address or Subnet. The zone protection applies to the whole traffic in this zone. You could deactivate the zone protection and try to add a DoS Protection Rule which is configured like the zone protection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Dec 2014 16:53:37 GMT</pubDate>
    <dc:creator>Wenar</dc:creator>
    <dc:date>2014-12-03T16:53:37Z</dc:date>
    <item>
      <title>Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41363#M30396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a highly regulated environment with multiple internal security zones. We need to be able to run our vulnerability scanning solution against servers in separate zones on a routine basis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was simple to exempt the scanner's IP from the Threat Prevention stuff (created a new security profile group which alerts on everything instead of blocking, and created a rule in the ACL to match against the scanner IP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the vulnerability scanner is still prevented from completing its job because of zone protection (specifically, port scanning). I would hate to have to disable the zone protection rules or change them to alert EVERY time we wish to run a scan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any wonderful ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2014 21:34:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41363#M30396</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-05-20T21:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41364#M30397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a workaround to do this by creating and zone without any zone protection and use the IPs that you would like to be exempted as the loopback interface IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The steps required can be found here.&lt;/P&gt;&lt;P&gt;How to Exempt a Specific IP address from Zone Protection&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="3972" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3972"&gt;https://live.paloaltonetworks.com/docs/DOC-3972&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this works for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Narong&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 May 2014 02:40:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41364#M30397</guid>
      <dc:creator>nchong</dc:creator>
      <dc:date>2014-05-21T02:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41365#M30398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hi&amp;nbsp; Mackwage,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;You can apply policy as u like and Mr. &lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Narong is right you can use the same. its help full.....&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Satish&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 May 2014 03:49:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41365#M30398</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-05-21T03:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41366#M30399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for you reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However it does not quite fit the scenario I am after. This seems like it would only work if you opened up one of your PUBLIC IPs. At that, it appears it would open up that public ip to port scanning from anywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All devices in this scenario are internal. There is no NAT. The vulnerablity appliance is internal and has a static IP. We need to be able to scan devices in other "internal" zones.. and would like to open up port scanning from only the source vulnerability scanner.. and no other IPs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 May 2014 20:34:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41366#M30399</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-05-21T20:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41367#M30400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the example it shows that the external IP is the one that is being exempted. But instead of using the external IP subnet you can use the internal IP subnet as the loopback address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 06:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41367#M30400</guid>
      <dc:creator>nchong</dc:creator>
      <dc:date>2014-05-22T06:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41368#M30401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We experienced a similar challenge and needed to allow our QSVs vulnerability scanners to bypass IDS/IPS and scan unobstructed for vulnerabilities.&amp;nbsp; We achieved this by adding a Security Rule to allow the scanner IPs (no profiles) on TCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This eliminated the Scan Interference our QSV scanners were experiencing.&amp;nbsp; This same approach should work internal-to-internal also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Nov 2014 18:54:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41368#M30401</guid>
      <dc:creator>AndrewHammond</dc:creator>
      <dc:date>2014-11-21T18:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41369#M30402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This can still cause interference as port scans are blocked by the Zone Protection profile which is configured at the zone level and not via an ACL rule. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Dec 2014 00:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41369#M30402</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-12-03T00:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41370#M30403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was a suggested way to resolve the issue from PA support and it did resolve &lt;SPAN style="text-decoration: underline;"&gt;our&lt;/SPAN&gt; specific scan interference issues, but I agree it may not be the end all be all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Dec 2014 14:49:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41370#M30403</guid>
      <dc:creator>AndrewHammond</dc:creator>
      <dc:date>2014-12-03T14:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41371#M30404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see a way to create an exception for one IP-Address or Subnet. The zone protection applies to the whole traffic in this zone. You could deactivate the zone protection and try to add a DoS Protection Rule which is configured like the zone protection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Dec 2014 16:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41371#M30404</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2014-12-03T16:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41372#M30405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the link is no more accessable....&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; background-color: #f3e1dd;"&gt;Access to this place or content is restricted. If you think this is a mistake, please contact your administrator or the person who directed you here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone provide the details or is there another solution ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2015 14:57:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/41372#M30405</guid>
      <dc:creator>mseiler</dc:creator>
      <dc:date>2015-01-30T14:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/63565#M38231</link>
      <description>&lt;P&gt;Echoing last comment as the mentioned DOC URI is gone. &amp;nbsp;Get's old quick my vuln scanners throwing up thousands of alerts each week every time they do a scan across (or in within) the same/different zones.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 22:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/63565#M38231</guid>
      <dc:creator>PeterT</dc:creator>
      <dc:date>2015-08-24T22:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/63575#M38233</link>
      <description>&lt;P&gt;Anyone found a solution to original post? Making an exception for a zone protection is still impossible? Because this is a serious isuue with many customers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 06:15:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/63575#M38233</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-08-25T06:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/63657#M38274</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a feature request # 1910.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whitelisting with Zone Protection (Reconnaissance).&amp;nbsp;&amp;nbsp; We have a handful of vulnerability scanners on campus use to scan our hosts and they are getting block by the zone protection profile.&amp;nbsp; We are wondering if there is a feature request for providing a white list to not get block by the zone protection profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This FR has been open for at least 2 years.&amp;nbsp; If you are interested, contact your sales person and sales engineer to add your company/name to the FR.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Last update that I got was, it is been consider in PAN OS 8.0, no confirmation yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 19:46:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/63657#M38274</guid>
      <dc:creator>workarounds</dc:creator>
      <dc:date>2015-08-26T19:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Except Specific IPs from port scan detection / Zone Protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/63754#M38317</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about combining two zone protection profiles? One that is aggressive, for the Untrust zone, and one that is permissive for the Trust zone, that will allow your "friendly" IPs to scan. Than create GP gateway for friendly IPs, push them the route towards Trust / DMZ / whatever you are scanning, and sort them out in their own "scanners" zone. Once they start scanning only permissive profile from the Trust zone will be applied to their scans, allowing them to finish the job. They are coming from separate scanners zone thus esily circumventing aggressive blocking profile on the Untrust zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 21:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/except-specific-ips-from-port-scan-detection-zone-protection/m-p/63754#M38317</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-27T21:28:58Z</dc:date>
    </item>
  </channel>
</rss>

