<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to shun/block an IP address for a period of time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44945#M32991</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You can change behaviour of signatures in vulnerability as shown in the picture (block for a periodic time).But for attempt count I don't think there is a way to do.Maybe you can write a custom signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1367" title="https://live.paloaltonetworks.com/docs/DOC-1367"&gt;https://live.paloaltonetworks.com/docs/DOC-1367&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="9068" alt="sc.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9068_sc.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 12 Oct 2013 19:43:46 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-10-12T19:43:46Z</dc:date>
    <item>
      <title>How to shun/block an IP address for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44944#M32990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've worked with several traditional IPS in the past and there is always a way to create rules that shun or block a source IP address for some period before automatically resetting.&amp;nbsp; It is especially useful for stopping automated bots that are just probing for flaws across the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifically, I'd like to create a rule that will monitor for failed login attempts to a web server located in a DMZ.&amp;nbsp; After 5 failed attempts in 2 minutes, I want to block the source IP address for 10 minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this be done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Oct 2013 14:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44944#M32990</guid>
      <dc:creator>njoyzrd</dc:creator>
      <dc:date>2013-10-12T14:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to shun/block an IP address for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44945#M32991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You can change behaviour of signatures in vulnerability as shown in the picture (block for a periodic time).But for attempt count I don't think there is a way to do.Maybe you can write a custom signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1367" title="https://live.paloaltonetworks.com/docs/DOC-1367"&gt;https://live.paloaltonetworks.com/docs/DOC-1367&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="9068" alt="sc.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9068_sc.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Oct 2013 19:43:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44945#M32991</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-12T19:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to shun/block an IP address for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44946#M32992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi njoyrzd,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would start with creating a schedule object under the objects tab. After this the schedule object can be used in a rule (under Options).&lt;/P&gt;&lt;P&gt;if it is not shown then it has to be enabled.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="option.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9072_option.PNG.png" /&gt;&lt;/P&gt;&lt;P&gt;right after this you can use the schedule object in the options field of the rule.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="opt.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9074_opt.PNG.png" /&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;Regards Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 06:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44946#M32992</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2013-10-14T06:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to shun/block an IP address for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44947#M32993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some of the "brute force" signatures have a picture of a pencil next to them, which allows you to Edit Time Attributes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="9081" alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/9081_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to shun based on an IPS signature that doesn't have a built-in time attribute, you can create a simple custom "combination" vulnerability signature.&amp;nbsp; Create a new custom vulnerability signature, enter some basic information on the "Configuration" tab (name, etc.), then on the signature type, choose "Combination".&amp;nbsp; Now, select the signature you wish to add some time attributes to.&amp;nbsp; (This example uses Threat ID 10005).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="9083" alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/9083_pastedImage_2.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next, go to the "Time Attribute" tab and add the # of hits within the # of seconds, and then how you wish to aggregate the data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="402" src="https://live.paloaltonetworks.com/legacyfs/online/9085_pastedImage_0.png" style="width: 801.779px; height: 402px;" width="802" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, with your new signature, you can change the action to "block-ip" (aka shun). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 15:49:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/44947#M32993</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-10-14T15:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to shun/block an IP address for a period of time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/449285#M100917</link>
      <description>&lt;P&gt;I apologize for the ignorant question, but I can't seem to find reference to what Threat ID &lt;EM&gt;10005&amp;nbsp;&lt;/EM&gt;denotes. Is this failed logins?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 17:41:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-shun-block-an-ip-address-for-a-period-of-time/m-p/449285#M100917</guid>
      <dc:creator>ISortOfKnowIT</dc:creator>
      <dc:date>2022-01-13T17:41:42Z</dc:date>
    </item>
  </channel>
</rss>

