<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sophos Antivirus in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48280#M35529</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was wondering if any one else has faced this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Sophos antivirus and when I create a rule with the vulnerability protection set to Strict, it blocks my connection to sophos server for updates.&amp;nbsp; Once I relax the VP rule, it looks fine.&amp;nbsp; Interestingly, I cannot see anything in the traffic/threat logs as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone faced such a situation and if yes, how was it managed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Kalyan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 May 2013 15:44:25 GMT</pubDate>
    <dc:creator>kalyanram.piratla</dc:creator>
    <dc:date>2013-05-07T15:44:25Z</dc:date>
    <item>
      <title>Sophos Antivirus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48280#M35529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was wondering if any one else has faced this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Sophos antivirus and when I create a rule with the vulnerability protection set to Strict, it blocks my connection to sophos server for updates.&amp;nbsp; Once I relax the VP rule, it looks fine.&amp;nbsp; Interestingly, I cannot see anything in the traffic/threat logs as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone faced such a situation and if yes, how was it managed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Kalyan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 15:44:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48280#M35529</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2013-05-07T15:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Antivirus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48281#M35530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you saying you have "log at session end" checked in the actions tab, and you still don't see them show up in the threat log?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 16:07:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48281#M35530</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-05-07T16:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Antivirus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48282#M35531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, as debugging, create a new profile where you set everything to alert that is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Critical: Alert&lt;/P&gt;&lt;P&gt;High: Alert&lt;/P&gt;&lt;P&gt;Medium: Alert&lt;/P&gt;&lt;P&gt;Low: Alert&lt;/P&gt;&lt;P&gt;Informational: Alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then create a new security rule (only for this particular srcip or if its dstip in your case) above the current one. In this new security rule attach the new vuln profile from above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you should hopefully see what is being identified for this traffic flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are not comfortable with setting all levels to Alert you can set them to Block (since this is just debug) - blocked traffic should be logged if you have set the "log on session end" (I guess "log on session start" wont pickup any threat).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However isnt the Threat log on its own not depending on what the security rule itself is set to? I mean I though the security rule was regarding Traffic logging. If a vuln should log or not is set in the vuln profile itself (such as Alert means log only while Block means block and log, while Allow will not log at all (for this you use Alert instead)).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 04:28:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48282#M35531</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-05-08T04:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Antivirus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48283#M35532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I do have it as Log at session end.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 07:03:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48283#M35532</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2013-05-08T07:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Antivirus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48284#M35533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mikand - I was under the impression that Vuln profiles with specific actions set does log the events under Threat Monitor.&amp;nbsp; None of the profiles have allow as an action, so I would ideally expect to see everything being logged in.&amp;nbsp; But that is not the case.&amp;nbsp; For some reason I cannot see any traffic or threat logs for Sophos updates.&amp;nbsp; But upon disabling the rule, the updates work but still nothing in the traffic or threat logs &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 07:06:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48284#M35533</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2013-05-08T07:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Antivirus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48285#M35534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try the suggestion that Mikand gave to create a new VP profile and set everything to alert? Have you updated the the application and threat signatures to the latest? Each CVE has an associated default action (allow, alert, reset, block). If you don't see anything in the threat log going to the dst address of sophos even after setting everything to alert, then It should not get blocked at any setting. If you do see it after setting everything to alert (like under informational threat) check to see what the CSV is set to as default for that CSV. If you don't see anything, I would open a case with TAC. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 13:03:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48285#M35534</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-05-09T13:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Sophos Antivirus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48286#M35535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried all means possible.&amp;nbsp; I am now raising it with TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 16:50:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sophos-antivirus/m-p/48286#M35535</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2013-05-09T16:50:00Z</dc:date>
    </item>
  </channel>
</rss>

