<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block IP address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4487#M3324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with the original poster and the feature he is requesting.&amp;nbsp; I'd like to be able to block the IP outright if it hits a certain threshold of threats without pre-determining which threats the attacker will hit (no way to know).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this feature coming? when?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Nov 2013 16:00:37 GMT</pubDate>
    <dc:creator>jshdpw</dc:creator>
    <dc:date>2013-11-21T16:00:37Z</dc:date>
    <item>
      <title>Block IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4483#M3320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to block a specific IP address if you detect multiple threats coming from this IP? For example block an IP address after the detection of 5 threats coming from this IP within 1 minute.&lt;/P&gt;&lt;P&gt;I know you can block an IP&amp;nbsp; but only as an action after the detection of a specific threat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 07:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4483#M3320</guid>
      <dc:creator>atticabank</dc:creator>
      <dc:date>2012-11-20T07:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4484#M3321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can block a source IP or combo source/dest pair for a time period using custom signatures.&amp;nbsp; Here's an example to block the source IP for threat 10353.&amp;nbsp; Make sure to select 'Combination' for signature type.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="4759" alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/4759_pastedImage_0.png" style="width: 598px; height: 284px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="4769" alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/4769_pastedImage_1.png" style="width: 603px; height: 249px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 15:34:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4484#M3321</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-11-20T15:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4485#M3322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. What about if I don't know the ThreatIDs? Lets suppose that the attacker runs a vulnerability scanner. Is it possible for the 'Condition' option to configure something like 'any threatID'?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2012 13:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4485#M3322</guid>
      <dc:creator>atticabank</dc:creator>
      <dc:date>2012-11-28T13:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4486#M3323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The custom signature method requires a selection of threatIDs.&amp;nbsp; For scanner detection, we can use DoS Protection to detect port scan, sweep, etc and block the source IP.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 19:11:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4486#M3323</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-11-30T19:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4487#M3324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with the original poster and the feature he is requesting.&amp;nbsp; I'd like to be able to block the IP outright if it hits a certain threshold of threats without pre-determining which threats the attacker will hit (no way to know).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this feature coming? when?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 16:00:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-address/m-p/4487#M3324</guid>
      <dc:creator>jshdpw</dc:creator>
      <dc:date>2013-11-21T16:00:37Z</dc:date>
    </item>
  </channel>
</rss>

