<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send ICMP Unreachable panos7 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/63451#M38175</link>
    <description>&lt;P&gt;Thanks for answer.I already know differences between drop and reset.I just wonder what extra gives icmp option ?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Aug 2015 06:52:40 GMT</pubDate>
    <dc:creator>PanIst</dc:creator>
    <dc:date>2015-08-21T06:52:40Z</dc:date>
    <item>
      <title>Send ICMP Unreachable panos7</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/6955#M5126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What really is the purpose of using that checkbox in policy action with drop or reset&amp;nbsp; ? What are benefits ? Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Aug 2015 21:43:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/6955#M5126</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2015-08-15T21:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Send ICMP Unreachable panos7</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/6956#M5127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Using reset and icmp unreachable is primarily aimed at traffic you expect you normal end user community to generate.&amp;nbsp; This gives a user a cleaner experience of the connection failure.&amp;nbsp; Their application gets an immediate response and stops the communication attempt.&amp;nbsp; And the application has an opportunity to give a failure message then to the user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Drop on the other hand is a silent activity where we basically ignore the traffic and the attempting application has no idea why the failure occurs.&amp;nbsp; This is the preferred response when the invalid traffic is expected from malicious sources, scanners, penetrators or other "bad actors".&amp;nbsp; An affirmative quick response lets them know a firewall is in the path and also shortens the time of their recon activities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both options apply only when we are preventing a connection, so in either case there is no session created. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Aug 2015 11:19:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/6956#M5127</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-08-16T11:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Send ICMP Unreachable panos7</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/63451#M38175</link>
      <description>&lt;P&gt;Thanks for answer.I already know differences between drop and reset.I just wonder what extra gives icmp option ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 06:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/63451#M38175</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2015-08-21T06:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Send ICMP Unreachable panos7</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/63511#M38202</link>
      <description>&lt;P&gt;Hi PanIst&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please take a look at&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/DotW-Send-ICMP-Unreachable-PAN-OS-7-0/ta-p/63507" target="_blank"&gt;DotW: Send ICMP Unreachable PAN-OS 7.0&lt;/A&gt;&amp;nbsp;where I tried to demonstrate more clearly what the icmp option does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 14:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/63511#M38202</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-09-15T14:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Send ICMP Unreachable panos7</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/76372#M42294</link>
      <description>&lt;P&gt;Hello Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the topic you have mentioned that the "Drop" action will silently discard all packets. My question is what will the user see at the backend. So for example if I have a policy to block a url using a custom url category and the action is set to "Deny"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will the user still see the reset page or it will keep loading ? When will it time out ? Can we change it ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I wanted to make correction. Pre 7.0 the only action available was Deny and not Drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 23:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/76372#M42294</guid>
      <dc:creator>Farman</dc:creator>
      <dc:date>2016-04-13T23:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Send ICMP Unreachable panos7</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/76383#M42297</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23408"&gt;@Farman﻿&lt;/a&gt;&amp;nbsp;WTR URL policy you're going to want to "Allow" the traffic in security policy and control the L7 / Web action via URL Profile; with an allow / alert / deny / continue / overide options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setting the URL profile with a deny action for a custom category or a default one will present the user matching the overall security policy with the URL response page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This response page can be of the default formatting from Palo or you can customize it to your company's own preference.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 00:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/send-icmp-unreachable-panos7/m-p/76383#M42297</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-14T00:32:09Z</dc:date>
    </item>
  </channel>
</rss>

