<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Quarantine functions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/quarantine-functions/m-p/44884#M32958</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean like a ratelimiting but for the Threat Prevention functions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO that doesnt make sense... you want to allow bad traffic but block the bad traffic for lets say 5 minutes and then allow the bad traffic again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or could you perhaps describe the usercase in more detail?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Feb 2012 19:11:01 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-02-01T19:11:01Z</dc:date>
    <item>
      <title>Quarantine functions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quarantine-functions/m-p/44883#M32957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have&amp;nbsp; a customer who is familiar with ISS Proventias.&amp;nbsp; This customer is trying to match capabilities of the ISS to PA.&amp;nbsp;&amp;nbsp; I have answered all his questiosn/ matchups with IPS rule to a Vulnerability Protection policy+ Malware/Spyware policy, but I am not sur ehow to address this quarantine question with him.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ISS Proventia, you can set a time limit to block traffic hitting an IPS rule, "quarantining" for a period of time.&amp;nbsp;&amp;nbsp; I can't seem to find this capabiity in the actions, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2012 17:10:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quarantine-functions/m-p/44883#M32957</guid>
      <dc:creator>cwilliams</dc:creator>
      <dc:date>2012-02-01T17:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantine functions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quarantine-functions/m-p/44884#M32958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean like a ratelimiting but for the Threat Prevention functions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO that doesnt make sense... you want to allow bad traffic but block the bad traffic for lets say 5 minutes and then allow the bad traffic again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or could you perhaps describe the usercase in more detail?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2012 19:11:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quarantine-functions/m-p/44884#M32958</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-01T19:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantine functions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quarantine-functions/m-p/44885#M32959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;cwilliams, is this an example you are thinking of?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Say that the Firewall detects a port scan from a particular IP address. What some IPS devices do is block that all traffic from that IP address for a certain amount of time, say 10 minutes. Once that timer expires, traffic is then permitted from that IP, until anoher violation occurs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2012 04:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quarantine-functions/m-p/44885#M32959</guid>
      <dc:creator>ekerstetter</dc:creator>
      <dc:date>2012-02-02T04:48:32Z</dc:date>
    </item>
  </channel>
</rss>

