<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic from PAN IP adresses in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119897#M45836</link>
    <description>&lt;P&gt;Thank you Tom. It is much appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Oct 2016 13:43:19 GMT</pubDate>
    <dc:creator>Netbooster</dc:creator>
    <dc:date>2016-10-18T13:43:19Z</dc:date>
    <item>
      <title>Traffic from PAN IP adresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119774#M45826</link>
      <description>&lt;P&gt;We are getting a lot of traffic on our website from certain IP-addresses registered to Palo Alto Networks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The addresses are&lt;/P&gt;&lt;P&gt;74.217.90.250,&lt;/P&gt;&lt;P&gt;154.59.123.106,&lt;/P&gt;&lt;P&gt;154.59.126.106,&lt;/P&gt;&lt;P&gt;70.42.131.106&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and several addresses on the 64.74.215.0/24 subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why do we get all of this traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can see by the patterns in the traffic that the tha traffic is from bots, but we would like to get to the bottom of the actual reason for all of this traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 08:36:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119774#M45826</guid>
      <dc:creator>Netbooster</dc:creator>
      <dc:date>2016-10-18T08:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from PAN IP adresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119823#M45827</link>
      <description>&lt;P&gt;Could you provide some more details?&lt;/P&gt;
&lt;P&gt;Did you or one of your colleagues perhaps open a support case that could require testing your site ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 10:26:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119823#M45827</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-18T10:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from PAN IP adresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119877#M45831</link>
      <description>&lt;P&gt;We run a large scandinavian affiliate network, and&amp;nbsp;it appears that our publisher's sites are crawled by those IP-addresses.&lt;/P&gt;&lt;P&gt;None of the publishers we have been in contact with have asked Palo Alto Networks to do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We recieve somewhere around 500.000 hits every month from 5 of Palo Alto Networks IP's&lt;/P&gt;&lt;P&gt;The main bulk of the traffic comes every day&amp;nbsp;between&amp;nbsp;03:00 and&amp;nbsp;08:00 UTC time.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 12:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119877#M45831</guid>
      <dc:creator>Netbooster</dc:creator>
      <dc:date>2016-10-18T12:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from PAN IP adresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119878#M45832</link>
      <description>&lt;P&gt;Ok that's pretty weird&lt;/P&gt;
&lt;P&gt;I've notified our internal departments to verify what's going on&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for notifying us!&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 12:35:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119878#M45832</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-18T12:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from PAN IP adresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119897#M45836</link>
      <description>&lt;P&gt;Thank you Tom. It is much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 13:43:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/119897#M45836</guid>
      <dc:creator>Netbooster</dc:creator>
      <dc:date>2016-10-18T13:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from PAN IP adresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/120048#M45861</link>
      <description>&lt;P&gt;A&amp;nbsp;couple of "legitimate" possibilities: &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Networks firewall users can configure their firewalls to scan e-mail delivered via SMTP. &amp;nbsp;The main use-case for this is to scan the content, drop known malware, and sandbox unknown malware. &amp;nbsp;Along the same lines, the firewall can also extract URL/hyperlinks and submit them to the WildFire cloud for pro-active analysis (looking for exploits &amp;amp; malware). &amp;nbsp;If there is a large amount of SMTP traffic including URLs that resolve to your address space, and those e-mails are being sent to WildFire subscribers, then this is one possibility. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Networks also has their own URL categorization engine, which will result in websites being crawled and periodically re-visited.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course, there are many other reasons why this could potentially be happening and I'd look to Tom to get you a more official answer. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 00:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-pan-ip-adresses/m-p/120048#M45861</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-10-19T00:17:12Z</dc:date>
    </item>
  </channel>
</rss>

