<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerability / AV / etc. Setup - Best initial approach in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-av-etc-setup-best-initial-approach/m-p/48917#M36025</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;if you need to enforce something, I suggest you tu use vwire mode (transparent).&lt;/P&gt;&lt;P&gt;Putting PAN in vwire is quite simple but it's better if some Network Administrator can help you (to have no downtime in the network).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create 2 policy (from trust to untrust and vice-versa) with IPS profile you desire but ALLOW all traffic to flow through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, look at Threat Log and start the tuning process &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have fun!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 04 Sep 2011 16:12:30 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2011-09-04T16:12:30Z</dc:date>
    <item>
      <title>Vulnerability / AV / etc. Setup - Best initial approach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-av-etc-setup-best-initial-approach/m-p/48915#M36023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm new to the 5060 and I'd like to phase in some IPS functionality over the next week.&amp;nbsp; This is a production system sitting in front of fairly busy site, so I'm a little nervous....&amp;nbsp; especially being totally new to the PAN OS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the best approach in configuring some of the IPS features and applying them to my front-end traffic?&amp;nbsp; Is there an easy way to apply this in a "transparent" mode so I can just see what it sees and then start to enforce blocking as needed from there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Aug 2011 15:23:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-av-etc-setup-best-initial-approach/m-p/48915#M36023</guid>
      <dc:creator>cmaier</dc:creator>
      <dc:date>2011-08-29T15:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability / AV / etc. Setup - Best initial approach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-av-etc-setup-best-initial-approach/m-p/48916#M36024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no simple answer as it differs from network to network.&amp;nbsp; But as you are new to PAN-OS, so it will be great if you could put our box in tap mode, create policy with security profiles (vulnerability, anti-spyware, AV) enabled using "alert" as the action. Then you will see what "we" see and draft your necessary plan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 02:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-av-etc-setup-best-initial-approach/m-p/48916#M36024</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-30T02:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability / AV / etc. Setup - Best initial approach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-av-etc-setup-best-initial-approach/m-p/48917#M36025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;if you need to enforce something, I suggest you tu use vwire mode (transparent).&lt;/P&gt;&lt;P&gt;Putting PAN in vwire is quite simple but it's better if some Network Administrator can help you (to have no downtime in the network).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create 2 policy (from trust to untrust and vice-versa) with IPS profile you desire but ALLOW all traffic to flow through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, look at Threat Log and start the tuning process &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have fun!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Sep 2011 16:12:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-av-etc-setup-best-initial-approach/m-p/48917#M36025</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-09-04T16:12:30Z</dc:date>
    </item>
  </channel>
</rss>

