<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow and then drop in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71448#M40797</link>
    <description>&lt;P&gt;If this is a user and&amp;nbsp;you're seeing a lot of threat logs matching his or her IP address, it would certainly warrant you taking a look and running a couple of virus scans on the machine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2016 14:17:06 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-01-22T14:17:06Z</dc:date>
    <item>
      <title>Allow and then drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71440#M40792</link>
      <description>&lt;P&gt;I have traffic that is showing up and allowed and dropped. What does that mean?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 13:17:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71440#M40792</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-01-22T13:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Allow and then drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71441#M40793</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you show us an example through a screenshot ?&lt;/P&gt;
&lt;P&gt;It may be that you have logging set to start and end of session and that a connection is first being allowed but later denied due to the application morphing into a blocked app&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 13:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71441#M40793</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-01-22T13:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Allow and then drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71443#M40794</link>
      <description>&lt;P&gt;Yes here it is&amp;nbsp;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2166i562A4E78C1BCF339/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="allowblock.png" title="allowblock.png" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 13:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71443#M40794</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-01-22T13:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Allow and then drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71446#M40795</link>
      <description>&lt;P&gt;if you look at the bottom 2 lines, you can see that in the column 'log' you have a threat entry and a traffic entry&lt;/P&gt;
&lt;P&gt;this means that the initial dns connection was allowed to go out to the internet, but then a malicious dns query was detected by a security profile (spyware) and blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there are 2 different databases that collect log information regarding a session:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="font-size: 12.88px; line-height: 18.4px;"&gt;traffic log: this simply records if a tcp connection is allowed through or not by security policy&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="font-size: 12.88px; line-height: 18.4px;"&gt;threat log: this records, independently of the traffic log, if a threat is detected and which action is taken, if any&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.88px; line-height: 18.4px;"&gt;so it's possible a sssion is allowed through by a security policy, but then after it has aleready started gets blocked because a threat is detected&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 13:58:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71446#M40795</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-01-22T13:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Allow and then drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71447#M40796</link>
      <description>&lt;P&gt;So as long as the users has spyware on his machine he will continue to back on the door of the PA and then get denied. According to the predefined report the user is number 5 of the top sessions on the PA should I be concerned about that?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 14:10:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71447#M40796</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-01-22T14:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Allow and then drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71448#M40797</link>
      <description>&lt;P&gt;If this is a user and&amp;nbsp;you're seeing a lot of threat logs matching his or her IP address, it would certainly warrant you taking a look and running a couple of virus scans on the machine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 14:17:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71448#M40797</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-01-22T14:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Allow and then drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71449#M40798</link>
      <description>&lt;P&gt;I agree but my helpdesk did not LOL.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 14:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-and-then-drop/m-p/71449#M40798</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-01-22T14:20:47Z</dc:date>
    </item>
  </channel>
</rss>

