<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create a blacklist with certain ip sources? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48738#M35891</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rule is my deny-all rule and I want to create another rule before it disabling the logging only for these attacking Ips. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gonzalo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Oct 2013 09:23:20 GMT</pubDate>
    <dc:creator>SOC_CSG</dc:creator>
    <dc:date>2013-10-18T09:23:20Z</dc:date>
    <item>
      <title>How to create a blacklist with certain ip sources?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48735#M35888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everybody&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I have is this. I have identifed about 70 attacking ips and I like to block completly the traffic from them (I already have and deny-rule in the bottom of my polices but this rule log the traffic). I like to create a rule to deny this traffic or a blacklist to include these ip address avoiding any kind of logging (syslog or SNMP trap)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GonzaloArroyo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 08:39:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48735#M35888</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2013-10-15T08:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a blacklist with certain ip sources?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48736#M35889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Not completely sure what you mean here.&lt;/P&gt;&lt;P&gt;But you can turn all logging on a rule off if you go into the rule and "action".&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Remove the "Log at Session End" option.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE cellspacing="0" class="x-table-layout" height="154" style="font-family: Tahoma, Arial, Helvetica, sans-serif; background-color: #ebedee; height: 154px; width: 396px;" width="396"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="x-table-layout-cell" colspan="1" rowspan="1" style="font-size: 11px;" valign="top"&gt;&lt;P class="x-form-label-left"&gt;&lt;/P&gt;&lt;DIV class="x-tab-item x-form-item" style="margin: 0 0 4px; font-family: tahoma, helvetica, arial, sans-serif; color: #222222;"&gt;&lt;LABEL class="x-form-item-label" for="ext-comp-6396" style="padding: 3px 3px 3px 0;"&gt;&lt;/LABEL&gt;&lt;DIV class="x-form-element" style="padding: 0 0 0 105px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;&lt;DIV class="x-form-check-wrap" style="padding: 3px 0;"&gt;&lt;DIV class="x-form-checkbox-inner" style="background-position: no-repeat no-repeat;"&gt;&lt;INPUT class="x-form-checkbox x-form-field" name="ext-comp-6396" style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12px;" tabindex="140" type="checkbox" /&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="x-form-cb-indentDiv" style="margin: 0 0 0 21px;"&gt;&lt;LABEL class="x-form-cb-label" for="ext-comp-6396" style="padding: 0 3px 0 0;"&gt;Log at Session Start&lt;/LABEL&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="x-table-layout-cell" colspan="1" rowspan="1" style="font-size: 11px;" valign="top"&gt;&lt;P class="x-form-label-left"&gt;&lt;/P&gt;&lt;DIV class="x-tab-item x-form-item" style="margin: 0 0 4px; font-family: tahoma, helvetica, arial, sans-serif; color: #222222;"&gt;&lt;LABEL class="x-form-item-label" for="ext-comp-6398" style="padding: 3px 3px 3px 0;"&gt;&lt;/LABEL&gt;&lt;DIV class="x-form-element" style="padding: 0 0 0 105px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;&lt;DIV class="x-form-check-wrap" style="padding: 3px 0;"&gt;&lt;DIV class="x-form-check-checked x-form-checkbox-inner" style="background-position: no-repeat no-repeat;"&gt;&lt;INPUT checked="checked" class="x-form-checkbox x-form-field" name="ext-comp-6398" style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12px;" tabindex="141" type="checkbox" /&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="x-form-cb-indentDiv" style="margin: 0 0 0 21px;"&gt;&lt;LABEL class="x-form-cb-label" for="ext-comp-6398" style="padding: 0 3px 0 0;"&gt;Log at Session End&lt;/LABEL&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jo Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 12:48:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48736#M35889</guid>
      <dc:creator>jochristian</dc:creator>
      <dc:date>2013-10-15T12:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a blacklist with certain ip sources?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48737#M35890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are several approaches you could choose from:&lt;/P&gt;&lt;P&gt;- The simplest approach would be to create a security rule higher in your rulebase (eg. test_rule) and list every attacking IP in the source address field of the rule 'test_rule'. To prevent traffic matching this rule from generating any logs, click on the rule&amp;gt;Actions&amp;gt;Log settings. Ensure that both "Log at session start" and "log at session end" are unchecked. Next, ensure that "Log Forwarding" profile is set to "None".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if you would like to use some sort of automation or external source to populate this list of source IPs, then you can look into creating the source IP address object using the PAN OS 5.0 features called "Dynamic Block List" or "Dynamic Address Objects".&lt;/P&gt;&lt;P&gt;Some references:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4121"&gt;https://live.paloaltonetworks.com/docs/DOC-4121&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-5850"&gt;https://live.paloaltonetworks.com/docs/DOC-5850&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4724"&gt;https://live.paloaltonetworks.com/docs/DOC-4724&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4118"&gt;https://live.paloaltonetworks.com/docs/DOC-4118&lt;/A&gt;&amp;nbsp; (Pg 241-242)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 13:01:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48737#M35890</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-10-15T13:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a blacklist with certain ip sources?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48738#M35891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rule is my deny-all rule and I want to create another rule before it disabling the logging only for these attacking Ips. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gonzalo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 09:23:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-blacklist-with-certain-ip-sources/m-p/48738#M35891</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2013-10-18T09:23:20Z</dc:date>
    </item>
  </channel>
</rss>

