<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Configure Action for 'automatic blocking an IP for an hour' in a vulnerability scanning? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64047#M38471</link>
    <description>&lt;STRIKE&gt;&lt;P&gt;baudy,&lt;/P&gt;&lt;/STRIKE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRIKE&gt;&lt;P&gt;The small screeshot size is due to the forum automatically resizing the images...&lt;/P&gt;&lt;/STRIKE&gt;&lt;STRIKE&gt;&lt;P&gt;Here are links to the full size versions:&lt;/P&gt;&lt;/STRIKE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRIKE&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/182i9469721019583E85" target="_blank"&gt;https://live.paloaltonetworks.com/t5/image/serverpage/image-id/182i9469721019583E85&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/183iFE1264D72159DFB2" target="_blank"&gt;https://live.paloaltonetworks.com/t5/image/serverpage/image-id/183iFE1264D72159DFB2&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/184iDA76937EF6AAE73C" target="_blank"&gt;https://live.paloaltonetworks.com/t5/image/serverpage/image-id/184iDA76937EF6AAE73C&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/181i461B7CCB2827410D" target="_blank"&gt;https://live.paloaltonetworks.com/t5/image/serverpage/image-id/181i461B7CCB2827410D&lt;/A&gt;&lt;/P&gt;&lt;/STRIKE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT:&amp;nbsp; COS has fixed the images in the original post.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2015 12:13:33 GMT</pubDate>
    <dc:creator>Bradley_Melton</dc:creator>
    <dc:date>2015-09-03T12:13:33Z</dc:date>
    <item>
      <title>How to Configure Action for 'automatic blocking an IP for an hour' in a vulnerability scanning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64021#M38449</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This would be possible to implement?&lt;BR /&gt;Configure my firewall to make a action for 'automatic blocking an IP for an hour' in a vulnerability scanning.&lt;/P&gt;&lt;P&gt;Objects -&amp;gt; Custom Objects -&amp;gt; Vulnerability&lt;/P&gt;&lt;P&gt;Example:&amp;nbsp;IP auto-block attacker for 1 hour, if 10 times in 10 seconds Any Scan Vulnerability Bash.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/197i55C42A5577A99EEC/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Imagen 1.jpg" title="Imagen 1.jpg" /&gt;&lt;/P&gt;&lt;P&gt;I want "OR" condition.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/198iCD5611FFBBFD4166/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Imagen 02.jpg" title="Imagen 02.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/199iA6CF63EB2356D815/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Imagen 15.jpg" title="Imagen 15.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/200iEAC88C0E21525F2E/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Imagen 16.jpg" title="Imagen 16.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here. addition to "IP address exemptions" should also have an option of "exemptions region".&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/201iDC0E4FA709236710/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Imagen 17.jpg" title="Imagen 17.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Last weekend we suffered a scan vulnerability Bash from different origins (countries).&amp;nbsp;&lt;/SPAN&gt;Do you think that might work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this worked well It could be a good method to persuade an attacker.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;dicu&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 09:24:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64021#M38449</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-09-03T09:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Action for 'automatic blocking an IP for an hour' in a vulnerability scanning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64032#M38460</link>
      <description>&lt;P&gt;Hi COS,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your screenshots are very small, I can't see any detail. What is in the OR condition? Is there a reason why you did not simply change the timer in the existing Bash remote code execution vulnerabilities? Did you really need a brute-force style vulnerability?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 18:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64032#M38460</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2015-09-02T18:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Action for 'automatic blocking an IP for an hour' in a vulnerability scanning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64047#M38471</link>
      <description>&lt;STRIKE&gt;&lt;P&gt;baudy,&lt;/P&gt;&lt;/STRIKE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRIKE&gt;&lt;P&gt;The small screeshot size is due to the forum automatically resizing the images...&lt;/P&gt;&lt;/STRIKE&gt;&lt;STRIKE&gt;&lt;P&gt;Here are links to the full size versions:&lt;/P&gt;&lt;/STRIKE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRIKE&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/182i9469721019583E85" target="_blank"&gt;https://live.paloaltonetworks.com/t5/image/serverpage/image-id/182i9469721019583E85&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/183iFE1264D72159DFB2" target="_blank"&gt;https://live.paloaltonetworks.com/t5/image/serverpage/image-id/183iFE1264D72159DFB2&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/184iDA76937EF6AAE73C" target="_blank"&gt;https://live.paloaltonetworks.com/t5/image/serverpage/image-id/184iDA76937EF6AAE73C&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/181i461B7CCB2827410D" target="_blank"&gt;https://live.paloaltonetworks.com/t5/image/serverpage/image-id/181i461B7CCB2827410D&lt;/A&gt;&lt;/P&gt;&lt;/STRIKE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT:&amp;nbsp; COS has fixed the images in the original post.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 12:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64047#M38471</guid>
      <dc:creator>Bradley_Melton</dc:creator>
      <dc:date>2015-09-03T12:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Action for 'automatic blocking an IP for an hour' in a vulnerability scanning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64057#M38476</link>
      <description>&lt;P&gt;Hi Bradley,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you have "and" condition, you wanted "or", that is the left out of two buttons circled in red square, they should all end up under a single "And condition 1".... as in:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/191i097D15C526CB9B14/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="rules.png" title="rules.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, direction should not be both, it is client2server, right? Server will not attack someone &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Besides all this, you will need to include this newly created vulnerability into your existing profile that applies to the security policy protecting this communication, I hope you didn't forget that part of the config &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 20:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64057#M38476</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-09-02T20:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Action for 'automatic blocking an IP for an hour' in a vulnerability scanning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64180#M38534</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I have two&amp;nbsp;questions about this:&lt;BR /&gt;How can I verify that the firewall are blocking the attacking IP?&lt;/P&gt;&lt;P&gt;.. I imagine in the logs (threat). &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;How can I check the time (timer) that carries a specific IP blocked?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;dicu&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 10:31:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64180#M38534</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-09-04T10:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Action for 'automatic blocking an IP for an hour' in a vulnerability scanning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64208#M38539</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will see an entry in the threat logs with the action "block-ip". To see the list of currently blocked IPs, use the following command in the CLI:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;debug dataplane show dos block-table&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to remove an IP address from the block list before the timer goes down to 0 :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;clear dos-protection zone &amp;lt;sourcezone&amp;gt; blocked source &amp;lt;ip-addr&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 17:43:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64208#M38539</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2015-09-04T17:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Action for 'automatic blocking an IP for an hour' in a vulnerability scanning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64394#M38625</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Interesting commands.&lt;BR /&gt;Command quite helpful in unlocking an IP (false positive).&amp;nbsp;I would also add the IP to the list of excluded. because otherwise it is likely that the IPS block again if detects a threat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much everybody.&lt;/P&gt;&lt;P&gt;dicu &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2015 08:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-action-for-automatic-blocking-an-ip-for-an-hour/m-p/64394#M38625</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-09-10T08:16:18Z</dc:date>
    </item>
  </channel>
</rss>

