<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerability Protection - Exceptions? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49162#M36227</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't test it myself but I'd say that would work as well. The firewall processes the security rules from top to bottom until a match is found. So if the new security rule above the old one is a match it would allow it and alert it in the Threat log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Feb 2013 11:04:09 GMT</pubDate>
    <dc:creator>oschuler</dc:creator>
    <dc:date>2013-02-15T11:04:09Z</dc:date>
    <item>
      <title>Vulnerability Protection - Exceptions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49158#M36223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've got one, okay, two little questions on the configuration of vulnerability protection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming we have a security policy configured with the pre-defined vulnerability protection profile named "strict". From that policy we're getting "LDAP: User Login Brute-force Attempt" (ID 40'005, severity high) log entries from time to time. The action is to drop all packets (because of the rule in place to block all critical, high and medium rated threats). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The queries are legitimate and we'd like to tweak the timing attributes for that specific threat ID. Now the first question is: What happens if we just change the timing values on that threat ID using the little pencil icon &lt;STRONG&gt;without&lt;/STRONG&gt; enabling the exception using the "Enable" check box in the first column? Will the new timing values be applied or is it mandatory to also check the Enable checkbox for the change to take effect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second question (just to be sure): What action is applied if we'd enable this threat ID in the exceptions tab? Is it correct that the default action for threat ID 40005 (which is set to alert only) would be applied?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any clarification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 19:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49158#M36223</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-02-14T19:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Protection - Exceptions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49159#M36224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you modify the vulnerability settings, you will need to use the &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;"Enable" check box&lt;/SPAN&gt;. If you don't, the changes you made will not take effect. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for your second question, when you enable the threat in the exceptions tab, the action defined on this signature will be used. In this case, alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 19:45:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49159#M36224</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-02-14T19:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Protection - Exceptions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49160#M36225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your very quick reply. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 19:47:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49160#M36225</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-02-14T19:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Protection - Exceptions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49161#M36226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As another workaround wouldnt it be possible to create an IPS profile which only contains this threat where you force it to alert (in case the default for the threat is block) and then in the security policy setup a new rule above the current one but with only the particular src/dstip which then uses this new IPS profile to bypass the check?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean in a situation where:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- The threat in question has block as default (but you want it to alert).&lt;/P&gt;&lt;P&gt;- At the same time as you only want to change this for a particular flow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 08:47:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49161#M36226</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-15T08:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Protection - Exceptions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49162#M36227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't test it myself but I'd say that would work as well. The firewall processes the security rules from top to bottom until a match is found. So if the new security rule above the old one is a match it would allow it and alert it in the Threat log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 11:04:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vulnerability-protection-exceptions/m-p/49162#M36227</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-02-15T11:04:09Z</dc:date>
    </item>
  </channel>
</rss>

