<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I see what is being blocked? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50646#M37296</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, I am new to Palo Alto... Which report will show what is being blocked? Do I create a Custom Report for that? I am really just interested in seeing what Palo Alto is blocking at this point. We just put it into service last Friday as strickly a Threat prevention/ anti-malware device for now and would like to show the boss - whom I had to convince to buy this - that we are blocking what we said we'd block.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Aug 2010 18:14:52 GMT</pubDate>
    <dc:creator>CWillms</dc:creator>
    <dc:date>2010-08-30T18:14:52Z</dc:date>
    <item>
      <title>How can I see what is being blocked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50646#M37296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, I am new to Palo Alto... Which report will show what is being blocked? Do I create a Custom Report for that? I am really just interested in seeing what Palo Alto is blocking at this point. We just put it into service last Friday as strickly a Threat prevention/ anti-malware device for now and would like to show the boss - whom I had to convince to buy this - that we are blocking what we said we'd block.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 18:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50646#M37296</guid>
      <dc:creator>CWillms</dc:creator>
      <dc:date>2010-08-30T18:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see what is being blocked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50647#M37297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are basic reports under the monitor tab that run every night around 2 to 4 AM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also create custom reports and have them emailed to you daily.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would look under the Threat Reports for what you are interested in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 18:41:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50647#M37297</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2010-08-30T18:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see what is being blocked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50648#M37298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at&amp;nbsp; Monitor/traffic reports&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Denied Sources, Denied Destination, unknownTCP, UDP sessions&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Aug 2010 21:51:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50648#M37298</guid>
      <dc:creator>leole</dc:creator>
      <dc:date>2010-08-31T21:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see what is being blocked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50649#M37299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You wanted to know how to log traffic that is denied. The default deny policy for zone to zone does not log those sessions that are denied by the default denies. &lt;BR /&gt;&lt;BR /&gt;To log this traffic all you need to do is create an any to any default deny or create explicit zone to zone deny policies. &lt;BR /&gt;&lt;BR /&gt;This policy must be place at the bottom of all your policies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 00:21:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50649#M37299</guid>
      <dc:creator>mthomasson</dc:creator>
      <dc:date>2010-09-01T00:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see what is being blocked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50650#M37300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;by default PAN firewalls don't log the traffic that is blocked by the implied block rule (remember that there is an implied block rule at the bottom of your security policy).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you want to log "all the rest of the traffc" (ie. traffic that isn't blocked by an existing rule) then you would need to add an explicit block rule to log the blocks that are, by default, done as part of the implied rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a rule with the characteristics listed below could be placed at the bottom of your policy list and that would do the trick:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;src zone: trust&amp;nbsp; &lt;/P&gt;&lt;P&gt;dst zone: untrust&lt;/P&gt;&lt;P&gt;src address: any&lt;/P&gt;&lt;P&gt;src user: any&lt;/P&gt;&lt;P&gt;dest addr: any&lt;/P&gt;&lt;P&gt;application: any&lt;/P&gt;&lt;P&gt;service: any&lt;/P&gt;&lt;P&gt;action : deny&lt;/P&gt;&lt;P&gt;profile: none&lt;/P&gt;&lt;P&gt;options: default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this should cause the PAN device to log all the dropped traffic so that you can demonstrate everything that is being blocked to your boss. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;reports depend upon logs for their creation. You can see how the implied block rule (which doesn't create logs) would not create the log data that &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;biggest caveat with an explicit global block rule is that if you choose any/any for the src and dst zones you will cause some undesirable behavior. So make sure to explicitly choose zones on this type of rule. and test in a lab before you do anything in production &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 02:43:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50650#M37300</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2010-09-01T02:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see what is being blocked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50651#M37301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rats - I knew I should have asked for a test box too. I got them to buy 2 HA pairs for production. Get this, my bosses boss, who was the biggest roadblock because Palo Alto doesn't have a Cisco sign above the door like IronPort does, topped the very first Spyware report on day one!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's poetic justice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks all for the good answers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Sep 2010 02:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50651#M37301</guid>
      <dc:creator>CWillms</dc:creator>
      <dc:date>2010-09-04T02:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see what is being blocked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50652#M37302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Sep 2010 02:05:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-what-is-being-blocked/m-p/50652#M37302</guid>
      <dc:creator>CWillms</dc:creator>
      <dc:date>2010-09-04T02:05:06Z</dc:date>
    </item>
  </channel>
</rss>

