<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA500 says virus - virus total says no in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44674#M32791</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Support mechanism of PANW is rather simple - contact your reseller as he probably is your first line of support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jun 2014 15:05:28 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2014-06-18T15:05:28Z</dc:date>
    <item>
      <title>PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44666#M32783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a bunch of files that we created that we need to upload via ftp to a remote server through the PA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The files trip the virus detector in the PA.&amp;nbsp; Here's a syslog entry with some identifying information changed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2014-06-16T15:22:31+10:00 10.84.1.33 [user warning] 22:31,000XXXXXXX,THREAT,virus,1,2014/06/16 15:22:25,10.84.20.250,50.28.93.0,0.0.0.0,0.0.0.0,I2E-ftp-rule-ftp,,,ftp,vsys1,Interior,External,ethernet1/2,ethernet1/1,mylog,2014/06/16 15:22:30,41521,1,36871,32182,0,0,0x0,tcp,deny,"myfile-06.06.0000-Beta-win64.exe",Virus/Win32.WGeneric.cpfjf(2455553),any,medium,client-to-server,236674,0x0,10.0.0.0-10.255.255.255,United States,0,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I scanned these files with several AV programs including clamav and I was able to upload it to virustotal (through the PA!) where it scanned completely clean.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I turn off virus checking on our ftp rule then someone may be able to download files with viruses so I don't want to do that but we need these files uploaded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to do that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2014 06:31:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44666#M32783</guid>
      <dc:creator>gmoss</dc:creator>
      <dc:date>2014-06-16T06:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44667#M32784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/14296"&gt;gmoss&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead turning off the AV scan for the entire rule, you can put a threat exception for that Threat ID (2455553) in the relevant AV profile. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a document that explains the same:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3699"&gt;How to Add a Threat Exceptions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or you can also exempt the IP addresses for that threat, so that exception is applied to a particular set of source and destination IP addresses. This is&amp;nbsp; more granular approach than the previous one:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5235"&gt;How To Add Exempt IP Addresses From the Threat Monitor Logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2014 15:01:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44667#M32784</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2014-06-16T15:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44668#M32785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding a threat exception means that if we ever get one of those we wouldn't be protected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to be able to upload OK but have files tested on download.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your answer, while helpful, doesn't answer the problem that we created these files and no-one else could find a virus in them. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the "how to add exempt ip addresses" but it didn't work.&amp;nbsp; I never get anything in the lower boxes and I never get an add button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a new AV profile for this rule with this virus exempted from the list.&amp;nbsp; But as I said, this won't protect us in the case someone tries to download a file that really has this virus.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2014 00:52:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44668#M32785</guid>
      <dc:creator>gmoss</dc:creator>
      <dc:date>2014-06-17T00:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44669#M32786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Gmoss,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you are correct. If you add&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; a threat exception, that means, for the time being you&amp;nbsp; wouldn't be protected. But, you always have an option to open a support case and provide detail information to modify the database in future release. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Secondly, there is no option to add exempt ip address on "Anti-Virus" profile. That option is avilable for "Vulnerability-profile".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;FYI:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;IMG alt="antivirus.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13956_antivirus.JPG" style="height: 400px; width: 620px;" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2014 02:29:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44669#M32786</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-17T02:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44670#M32787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It'd be good to open a support case but how do I do that?&amp;nbsp; Every time I use this site everything has changed.&amp;nbsp; When I try and make a support case I get redirected to salesforce.com and I have no login there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2014 01:41:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44670#M32787</guid>
      <dc:creator>gmoss</dc:creator>
      <dc:date>2014-06-18T01:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44671#M32788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Hello Gmoss,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If you have a valid support contact with PAN ,Please login into &lt;A href="https://support.paloaltonetworks.com/" title="https://support.paloaltonetworks.com/"&gt;https://support.paloaltonetworks.com/&lt;/A&gt; and go to Case-Management. There you can create a&amp;nbsp; new support case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;OR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;SPAN&gt;Please drop an email to &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:support@paloaltonetworks.com"&gt;support@paloaltonetworks.com&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2014 01:50:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44671#M32788</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-18T01:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44672#M32789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like I said when I go there and click on case management I get redirected to a salesforce.com login page.&amp;nbsp; I have no idea what to do then&amp;nbsp; I have no salesforce login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I finally got the redirect to work but I can't apparently log a case because my support has to go through another company.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2014 02:54:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44672#M32789</guid>
      <dc:creator>gmoss</dc:creator>
      <dc:date>2014-06-18T02:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44673#M32790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you click on the Case Management link, you should be taken to the following page.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-06-18_07-42-09.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13999_2014-06-18_07-42-09.png" style="height: 199px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Click on the New Case button to open a case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you still encounter issues, open a case by calling Support.&amp;nbsp; Refer to &lt;A href="https://www.paloaltonetworks.com/company/contact-us.html" title="https://www.paloaltonetworks.com/company/contact-us.html"&gt;Contact Us&lt;/A&gt; for Support phone numbers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2014 14:47:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44673#M32790</guid>
      <dc:creator>panagent</dc:creator>
      <dc:date>2014-06-18T14:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 says virus - virus total says no</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44674#M32791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Support mechanism of PANW is rather simple - contact your reseller as he probably is your first line of support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2014 15:05:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-says-virus-virus-total-says-no/m-p/44674#M32791</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-06-18T15:05:28Z</dc:date>
    </item>
  </channel>
</rss>

