<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block-ip action for blocking brute force ssh doesn't seem to be working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48428#M35641</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you tell me how that rule is configured?&amp;nbsp; I use the GUI more.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Jan 2013 16:37:46 GMT</pubDate>
    <dc:creator>MemphisBrothers</dc:creator>
    <dc:date>2013-01-31T16:37:46Z</dc:date>
    <item>
      <title>Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48427#M35640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;We've been noticing that we are getting quite a bit of brute force ssh attempts on our system, so we decided tonight to put in a rule that blocks those attempts. I took one of our existing policies that just logs everything, and added an exception that would block ssh brute forcing. Originally the action we set was block-ip, and we set it to block the ip for 30 minutes. However, when I ran a brute forcer against one of our servers, I saw all my connections coming in (about 3k) and it showed up in the monitor log as a brute force threat. Even though it classified as a threat, it doesn't seem that it blocked my ip at all. I ran the test multiple times and it kept detecting me, but not blocking me. &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;I then switched the action to drop, and it worked great, it blocked me after about 20 attempts. Anyone know why the block-ip action wouldn't work, but drop would? Also, seems like it took about 5 minutes until I could SSH back in. That time is probably fine, but anyone know how long it's supposed to start accepting packets from an ip address once it has detected a threat?&lt;/P&gt;&lt;DIV&gt;Thanks for your help.&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 16:15:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48427#M35640</guid>
      <dc:creator>Landon</dc:creator>
      <dc:date>2013-01-31T16:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48428#M35641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you tell me how that rule is configured?&amp;nbsp; I use the GUI more.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 16:37:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48428#M35641</guid>
      <dc:creator>MemphisBrothers</dc:creator>
      <dc:date>2013-01-31T16:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48429#M35642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The security policy is configured to only allow SSH, ping and rsync connections from all destinations. The rule for vulnerabilities is to alert on all medium to critical vulnerabilities. We added an exception for the SSH Brute Force vulnerability, since we were seeing quite a few in the logs. Originally, the action on the exception was block-ip for 30 minutes, which wasn't working. We then set the action to drop, and it worked fine. Is that enough information to make it clearer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 16:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48429#M35642</guid>
      <dc:creator>Landon</dc:creator>
      <dc:date>2013-01-31T16:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48430#M35643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone have any ideas? Palo Alto, you there?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 02:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48430#M35643</guid>
      <dc:creator>Landon</dc:creator>
      <dc:date>2013-02-08T02:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48431#M35644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What PAN-OS version are you running?&amp;nbsp; Which platform? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use use the block-ip action with the Brute-Force SSH signature and it works well in my environment.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 18:17:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48431#M35644</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-02-08T18:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48432#M35645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're running PANOS 4.1.6 on a PA-5020&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 18:33:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48432#M35645</guid>
      <dc:creator>Landon</dc:creator>
      <dc:date>2013-02-08T18:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48433#M35646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You'll want to check with TAC directly, but I believe there were a few issues specifically with the "block-ip" action that were addressed as part of the 4.1.7 PAN-OS release.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 18:47:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48433#M35646</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-02-08T18:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48434#M35647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a changelog for 4.1.7 I could look through? I'm not finding it in the documentation section.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 18:51:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48434#M35647</guid>
      <dc:creator>Landon</dc:creator>
      <dc:date>2013-02-08T18:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Block-ip action for blocking brute force ssh doesn't seem to be working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48435#M35648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The release notes will contain a section 'Addressed Issues' that will list customer found problems. Release Notes can be found Support site -&amp;gt; Software Updates or in the Device WebUI(Device-&amp;gt;Software).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are a couple of bugs fixed in 4.1.7 related to block-ip:&lt;/P&gt;&lt;P&gt;41427 – On platforms that contain multiple data planes, aggregate DoS protection rules &lt;/P&gt;&lt;P&gt;do not properly enforce block IP actions if the session is hosted by a dataplane other than &lt;/P&gt;&lt;P&gt;dataplane zero.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;41331 – On platforms that contain multiple dataplanes, block IP actions using custom &lt;/P&gt;&lt;P&gt;vulnerability definitions are not enforced properly unless the session is being processed by &lt;/P&gt;&lt;P&gt;dataplane zero.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 19:41:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-action-for-blocking-brute-force-ssh-doesn-t-seem-to-be/m-p/48435#M35648</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2013-02-08T19:41:18Z</dc:date>
    </item>
  </channel>
</rss>

