<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic vulnerability block action in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48216#M35468</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when creating a profile choosing block action is seen as "reset-both" on the logs.&lt;/P&gt;&lt;P&gt;is that normal behaviour or not ? Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="just_one_rule.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15634_just_one_rule.png" style="height: 460px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="logsrelated.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15638_logsrelated.png" style="height: 43px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Sep 2014 13:29:33 GMT</pubDate>
    <dc:creator>PanIst</dc:creator>
    <dc:date>2014-09-18T13:29:33Z</dc:date>
    <item>
      <title>vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48216#M35468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when creating a profile choosing block action is seen as "reset-both" on the logs.&lt;/P&gt;&lt;P&gt;is that normal behaviour or not ? Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="just_one_rule.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15634_just_one_rule.png" style="height: 460px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="logsrelated.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15638_logsrelated.png" style="height: 43px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2014 13:29:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48216#M35468</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2014-09-18T13:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48217#M35469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Panlst,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an expected behavior. In this case, the PAN firewall blocked that Vulnerability and send TCP RST packet to both parties &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;Server and client) to close the connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2014 14:55:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48217#M35469</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-18T14:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48218#M35470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PA should probably update the help file for these vulnerability options.&amp;nbsp; The wording is ambiguous and I assume that block was a drop and not a reset action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="TB_TableBody"&gt;&lt;A name="1583572"&gt;Action&lt;/A&gt;&lt;/P&gt;&lt;P class="TB_TableBody"&gt;&lt;A name="1583574"&gt;Choose the action (&lt;/A&gt;&lt;SPAN style="font-weight: bold;"&gt;Alert&lt;/SPAN&gt;, &lt;SPAN style="font-weight: bold;"&gt;Allow&lt;/SPAN&gt;, &lt;SPAN style="font-weight: bold;"&gt;Default&lt;/SPAN&gt;, or &lt;SPAN style="font-weight: bold;"&gt;Block&lt;/SPAN&gt;) to take when the rule is triggered. The &lt;SPAN style="font-weight: bold;"&gt;Default&lt;/SPAN&gt; action is based on the pre-defined action that is part of each signature provided by Palo Alto Networks. To view the default action for a signature, navigate to Objects &amp;gt; Security Profiles &amp;gt; Vulnerability Protection and click &lt;SPAN style="font-weight: bold;"&gt;Add&lt;/SPAN&gt; or select an existing profile. Click the &lt;SPAN style="font-weight: bold;"&gt;Exceptions &lt;/SPAN&gt;tab and then click &lt;SPAN style="font-weight: bold;"&gt;Show all signatures&lt;/SPAN&gt;. A list of all signatures will displayed and you will see an &lt;SPAN style="font-weight: bold;"&gt;Action &lt;/SPAN&gt;column.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2014 15:08:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48218#M35470</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-09-18T15:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48219#M35471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Hello Panlst,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;As per the screenshots attached in this discussion thread, the firewall identifies the vulnerability with &lt;STRONG&gt;threat&lt;/STRONG&gt; &lt;STRONG&gt;ID: 35107&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;IMG __jive_id="15637" alt="Vulnerability-reset-action-1.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15637_Vulnerability-reset-action-1.jpg" style="height: 61px; width: 620px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If you check the default action of this Vulnerability signature, is to reset the connection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2014 15:08:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48219#M35471</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-18T15:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48220#M35472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But PanLst is choosing "Block" not "Default" for the action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The help file does not specify which action occurs with "Block" drop or reset.&amp;nbsp; Are you saying above that the action is reset both?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2014 15:21:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48220#M35472</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-09-18T15:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48221#M35473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;but we choose block not default.There is something wrong here.Block = reset both&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2014 07:25:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48221#M35473</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2014-09-19T07:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48222#M35474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Panlst,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My apologies, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; understand it wrongly. You are correct, As per the DOC: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1522"&gt;Vulnerability Profile Actions&lt;/A&gt;&amp;nbsp; if traffic is hitting this vulnerability-protection rule, it should simply d&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; text-align: center;"&gt;rop all packets for that session.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please provide a snapshot of the traffic logs and security rule, just to confirm&amp;nbsp; the vulnerability rule "ALL" applied to the correct policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2014 15:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48222#M35474</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-19T15:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48223#M35475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi HULK;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I replicated that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the screens.I think there is something wrong with definitions or explanations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="4.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15831_4.png" style="height: 322px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="3.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15832_3.png" style="height: 81px; width: 620px;" /&gt;&lt;IMG alt="2.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/15833_2.png" style="height: 379px; width: 620px;" /&gt;&lt;IMG alt="1.png" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/15834_1.png" style="height: 111px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 20:58:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48223#M35475</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-09-26T20:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48224#M35476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The default action is defined by Palo Alto Networks on a per-threat basis as either alert or block. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every vulnerability has a "block" behavior.&amp;nbsp; Some block behaviors send a reset to the server or client, or in this case, both.&amp;nbsp; For this example the default action is block, and the block behavior is reset-both.&amp;nbsp; Even though the action being taken is block, the threat log will show the block behavior that was used to terminate the session under the action column.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quick edit:&lt;/P&gt;&lt;P&gt;If you want to change the "block" behavior for a threat, you must configure an exception.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 21:21:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48224#M35476</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2014-09-26T21:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48225#M35477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for answer.&lt;/P&gt;&lt;P&gt;So block behaviour should be added somewhere on the guides as definiton also I think.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 21:25:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/48225#M35477</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-09-26T21:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability block action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/525568#M108689</link>
      <description>&lt;P&gt;It's hard form me make Definition to any of this &lt;STRONG&gt;Threat ID, &lt;/STRONG&gt;Like&amp;nbsp;XMRig Miner Command and Control Traffic Detection(85886) or&amp;nbsp;MVPower DVR Shell Unauthenticated Command Execution Vulnerability(57566).&lt;BR /&gt;&amp;nbsp;Do you have any guide or E-Book for make any definition of &lt;STRONG&gt;Threat ID.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 09:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-block-action/m-p/525568#M108689</guid>
      <dc:creator>Aryanto</dc:creator>
      <dc:date>2022-12-31T09:20:58Z</dc:date>
    </item>
  </channel>
</rss>

