<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BlackNurse Testing Causes issues on Egress Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131538#M46967</link>
    <description>&lt;P&gt;FYI It doesn't appear to require an&amp;nbsp;attack to be an IP address bound to the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It also appears that testing a remote firewall while egressing through a PA firewall causes your local firewall to experience DOS effects. It is not just inbound to an IP address of a PA's interface or NAT to that interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did an hping3 of type 3 to a remote PA-3020 to test my flood protection in a Zone Protection configuration. In doing so, many of our cloud services became unresponsive through our HQ PA-5060 firewall the testing client was behind.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2016 18:32:41 GMT</pubDate>
    <dc:creator>bspilde</dc:creator>
    <dc:date>2016-12-06T18:32:41Z</dc:date>
    <item>
      <title>BlackNurse Testing Causes issues on Egress Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131538#M46967</link>
      <description>&lt;P&gt;FYI It doesn't appear to require an&amp;nbsp;attack to be an IP address bound to the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It also appears that testing a remote firewall while egressing through a PA firewall causes your local firewall to experience DOS effects. It is not just inbound to an IP address of a PA's interface or NAT to that interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did an hping3 of type 3 to a remote PA-3020 to test my flood protection in a Zone Protection configuration. In doing so, many of our cloud services became unresponsive through our HQ PA-5060 firewall the testing client was behind.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 18:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131538#M46967</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2016-12-06T18:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: BlackNurse Testing Causes issues on Egress Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131562#M46971</link>
      <description>&lt;P&gt;It sounds like you hit the CPS limits of your device, which in affect would be almost the same as a DOS. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 19:25:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131562#M46971</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-06T19:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: BlackNurse Testing Causes issues on Egress Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131593#M46972</link>
      <description>&lt;P&gt;Sitting at 900 peak out of 120,000 on a regular basis so I don't think that was it. I'll test again specifically watching CPS in show session info as well as CPU utilization. As I recall, our Egress PA did not have any noticible fluctuations in CPU utilization during the hping3 test.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 21:01:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131593#M46972</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2016-12-06T21:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: BlackNurse Testing Causes issues on Egress Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131757#M46978</link>
      <description>&lt;P&gt;Interesting; keep us posted. Unless I'm completely remembering things wrong the PA wasn't supposed to be affected by this unless you hit the CPS limit due to someone trying to launch the attach.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 14:04:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacknurse-testing-causes-issues-on-egress-firewall/m-p/131757#M46978</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-07T14:04:27Z</dc:date>
    </item>
  </channel>
</rss>

