<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Action Configured in Security Rules and Seen in Traffic Log is Inconsistent 7.04 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70246#M40476</link>
    <description>&lt;P&gt;Since upgrading to 7.0.4 our traffic logs now show&amp;nbsp;the action of 'reset-both' and 'deny' when the rule explicitly has been set to 'deny'. This is occuring on multiple rules since upgrading from 6.1.8.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example: we have a rule to block specific applications like bittorent, http-proxy,&amp;nbsp;hola-unblocker,&amp;nbsp;etc and the action is set to 'deny'. But now we see a mixture of 'deny' and or 'reset-both' for this&amp;nbsp;rule. Before upgrading to 7.0.4 the action was always 'deny' as this is how the rule was setup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this to be expected? If so is there somewhere to read the explination?&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jan 2016 19:00:47 GMT</pubDate>
    <dc:creator>lewis</dc:creator>
    <dc:date>2016-01-04T19:00:47Z</dc:date>
    <item>
      <title>Action Configured in Security Rules and Seen in Traffic Log is Inconsistent 7.04</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70246#M40476</link>
      <description>&lt;P&gt;Since upgrading to 7.0.4 our traffic logs now show&amp;nbsp;the action of 'reset-both' and 'deny' when the rule explicitly has been set to 'deny'. This is occuring on multiple rules since upgrading from 6.1.8.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example: we have a rule to block specific applications like bittorent, http-proxy,&amp;nbsp;hola-unblocker,&amp;nbsp;etc and the action is set to 'deny'. But now we see a mixture of 'deny' and or 'reset-both' for this&amp;nbsp;rule. Before upgrading to 7.0.4 the action was always 'deny' as this is how the rule was setup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this to be expected? If so is there somewhere to read the explination?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2016 19:00:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70246#M40476</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2016-01-04T19:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Action Configured in Security Rules and Seen in Traffic Log is Inconsistent 7.04</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70322#M40487</link>
      <description>&lt;P&gt;Do you have a security profile attached to the rule?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm wondering if that traffic may be hitting a threat id&amp;nbsp;that has an action for reset both.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 11:26:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70322#M40487</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-01-05T11:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Action Configured in Security Rules and Seen in Traffic Log is Inconsistent 7.04</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70342#M40491</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23536"&gt;@lewis﻿&lt;/a&gt;&lt;A href="https://downloads.paloaltonetworks.com/software/PAN-OS-7.0.4-RN.pdf?__gda__=1452055432_eb7de8c610922457f6e2196acd167d12" target="_blank"&gt;https://downloads.paloaltonetworks.com/software/PAN-OS-7.0.4-RN.pdf?__gda__=1452055432_eb7de8c610922457f6e2196acd167d12&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under Changes to Default Behavior&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"The default actions for handling threats now are alert or reset-both (sides of the connection). In releases prior to PAN-OS 7.0.0, the defaults were alert or block. On upgrade, the block action will be converted to reset-both; and the drop-packets option is now renamed as drop."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I looked at out "Application Deny Rule" which has no security profiles just the "deny" action selected and we've got "Reset-Both" as the action. &amp;nbsp;So I guess it's just not a "threat" but for any "Deny." &amp;nbsp;With the "drop" action now available. &amp;nbsp;I'm guessing that selecting "Deny" is going to be the same as selecting "reset-both."&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 14:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70342#M40491</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-01-05T14:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Action Configured in Security Rules and Seen in Traffic Log is Inconsistent 7.04</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70362#M40494</link>
      <description>&lt;P&gt;this was a part of my initial thinking too as we do have security profiles associated to the rules. However under further invesigation the traffic in question is not associated to any threat signatures.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 17:40:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70362#M40494</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2016-01-05T17:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Action Configured in Security Rules and Seen in Traffic Log is Inconsistent 7.04</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70363#M40495</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300" target="_blank"&gt;Brandon_Wertz&lt;/A&gt;. I will have a look at this&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 17:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/70363#M40495</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2016-01-05T17:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Action Configured in Security Rules and Seen in Traffic Log is Inconsistent 7.04</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/71569#M40837</link>
      <description>&lt;P&gt;I have since logged a ticket with support and they are still investigating as a possible bug as the action should only match what the policy is set too.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 17:57:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/71569#M40837</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2016-01-25T17:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Action Configured in Security Rules and Seen in Traffic Log is Inconsistent 7.04</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/71996#M40988</link>
      <description>&lt;P&gt;I just received notifaction from support indicating although the action is set to deny in the policy the actual action can be different.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/networking-features/granular-actions-for-blocking-traffic-in-security-policy.html#13774" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/networking-features/granular-actions-for-blocking-traffic-in-security-policy.html#13774&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2314i5ADF8F25A5584A22/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="action.JPG" title="action.JPG" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 18:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/action-configured-in-security-rules-and-seen-in-traffic-log-is/m-p/71996#M40988</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2016-02-02T18:29:05Z</dc:date>
    </item>
  </channel>
</rss>

