<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Threat prevention in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50619#M37269</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have downloaded and installed the threat prevention license, configured daily download of antivirus and the other downloads, created security profiles and added them to my security profiles. Everything is working except for the antivirus, its downloading and installing the definitions every day but I am not getting any information in my threat monitor for antivirus. I don't think I missed anything but let me know if anyone has any ideas.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Jun 2015 12:57:38 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2015-06-09T12:57:38Z</dc:date>
    <item>
      <title>Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50619#M37269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have downloaded and installed the threat prevention license, configured daily download of antivirus and the other downloads, created security profiles and added them to my security profiles. Everything is working except for the antivirus, its downloading and installing the definitions every day but I am not getting any information in my threat monitor for antivirus. I don't think I missed anything but let me know if anyone has any ideas.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 12:57:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50619#M37269</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-09T12:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50620#M37270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can test Your config by Eicar test AV &lt;A href="http://www.eicar.org/86-0-Intended-use.html" title="http://www.eicar.org/86-0-Intended-use.html"&gt;http://www.eicar.org/86-0-Intended-use.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 14:24:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50620#M37270</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-06-09T14:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50621#M37271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It collecting maleware and vulnerability data just fine it the antivirus portion of the threat prevention that isn't showing anything I don't think the link you gave me will help me to assure that my antivirus configuration is correct and working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 14:27:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50621#M37271</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-09T14:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50622#M37272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Opps - dorry for misunderstanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about Monitor&amp;gt;System logs close to time when update of AV definition should be picked up?&lt;/P&gt;&lt;P&gt;Did You try to manually upload AV update?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of PAN are You using?&lt;/P&gt;&lt;P&gt;Please share with us screenshot of Dynamic Update&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ragards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 15:41:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50622#M37272</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-06-09T15:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50623#M37273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My PA version is 6.1.1. Its downloading and installing just fine it just now showing any data&amp;nbsp; in the threat monitor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/20013_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 15:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50623#M37273</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-09T15:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50624#M37274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what about Your security rules - does it have AV profile atached?&lt;/P&gt;&lt;P&gt;something like that:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-06-09_202910.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20015_2015-06-09_202910.png" style="height: 338px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;in my example there is None - but You must chose one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 18:31:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50624#M37274</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-06-09T18:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50625#M37275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I have them created and added to my security policies&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 18:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50625#M37275</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-09T18:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50626#M37276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lets do a test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try to dwonload &lt;A class="loading" href="http://www.eicar.org/download/eicar.com" title="http://www.eicar.org/download/eicar.com"&gt;http://www.eicar.org/download/eicar.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If You really have proper configuration of AV profile atached to Your security polisy that allow Your computer to get internet access this Eicar file should be blocked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please atache Your session detail with atempt to download Eicar file. My is:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-06-09_205547.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20016_2015-06-09_205547.png" style="height: 402px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 18:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50626#M37276</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-06-09T18:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50627#M37277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did the testing and confirmed with the PA service desk that it is configured correctly but still is not working&amp;nbsp; correctly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2015 16:11:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50627#M37277</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-10T16:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50628#M37278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Slawek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your screen print for the sample rule should have an Antivirus profile that blocks traffic.&amp;nbsp; Like below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture-Rule-actions.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20014_Capture-Rule-actions.PNG" style="height: 404px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Profile view:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture-AV-Profile.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20033_Capture-AV-Profile.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just saw it was missing in your example and may have been an oversight on your part.&amp;nbsp; Hopefully this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2015 02:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50628#M37278</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2015-06-11T02:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50629#M37279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is not necessary to have it set to block to have it work, it can also be set to alert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2015 12:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50629#M37279</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-11T12:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50630#M37280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;True.&amp;nbsp; but having an Antivirus Profile of "none" will not work for testing.&amp;nbsp; That was the main point I was suggesting.&amp;nbsp; The block profile is just what we have in place.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2015 12:32:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50630#M37280</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2015-06-11T12:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50631#M37281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got this to respond to the eicar test recommended by PA support. But other than that it show no virus threats. That still doesn't seem possbile&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2015 19:58:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention/m-p/50631#M37281</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-12T19:58:42Z</dc:date>
    </item>
  </channel>
</rss>

