<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: scan-host sweep in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/133405#M47211</link>
    <description>Threshold is the number of events in the interval amount of time&lt;BR /&gt;So 100 hosts touched in 2 seconds for example&lt;BR /&gt;Zone protection is global for all traffic hitting a destination zone&lt;BR /&gt;&lt;BR /&gt;If you need to be more granular, to protect a single server's resources for example, you should use a DOS policy&lt;BR /&gt;&lt;BR /&gt;If you set action alert instead of block, you will simply see a log entry for each 'scan' but no action is taken</description>
    <pubDate>Sun, 18 Dec 2016 19:58:10 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-12-18T19:58:10Z</dc:date>
    <item>
      <title>scan-host sweep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/132790#M47124</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Under threat detection, scan host sweep &amp;nbsp;droped some traffic. And under the rules it did not show anything .&lt;/P&gt;&lt;P&gt;What does it mean&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2016 14:33:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/132790#M47124</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-12-14T14:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: scan-host sweep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/132959#M47138</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have a zone protection profile configured and you have configured an action for the host sweep scan?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fozail&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 06:25:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/132959#M47138</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-15T06:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: scan-host sweep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/132971#M47142</link>
      <description>&lt;P&gt;You probably have zone protection enabled&lt;/P&gt;
&lt;P&gt;'host sweep' is a reconnaissance attack where a host 'scans' several of your ip addresses&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zone protection.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="zone protection.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 08:12:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/132971#M47142</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-15T08:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: scan-host sweep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/133363#M47204</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;what is the interval and Threshold here .&lt;/P&gt;&lt;P&gt;how a zone protection profile integrated with a zone ?&lt;/P&gt;&lt;P&gt;for example if we have zone trust,server , how we assign the profile to the zone .&lt;/P&gt;&lt;P&gt;What if we change &amp;nbsp;from the block to alert ? .&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 18 Dec 2016 13:04:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/133363#M47204</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-12-18T13:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: scan-host sweep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/133405#M47211</link>
      <description>Threshold is the number of events in the interval amount of time&lt;BR /&gt;So 100 hosts touched in 2 seconds for example&lt;BR /&gt;Zone protection is global for all traffic hitting a destination zone&lt;BR /&gt;&lt;BR /&gt;If you need to be more granular, to protect a single server's resources for example, you should use a DOS policy&lt;BR /&gt;&lt;BR /&gt;If you set action alert instead of block, you will simply see a log entry for each 'scan' but no action is taken</description>
      <pubDate>Sun, 18 Dec 2016 19:58:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/133405#M47211</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-18T19:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: scan-host sweep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/134647#M47374</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I remember "Zone Protection Profile" applies on source zone not on destination zone, correct me if I am wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fozail&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 11:58:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/134647#M47374</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-27T11:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: scan-host sweep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/134659#M47377</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16044"&gt;@fozail&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Zone protection profile is designed to provide broad-based protection at the ingress zone (i.e. the zone where traffic enters the firewall) and is&amp;nbsp;not designed to protect a specific end host or traffic going to a particular destination zone. &amp;nbsp; Use the DoS protection rulebase to match on a specific zone, interface, IP address or user.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 14:28:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/134659#M47377</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-12-27T14:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: scan-host sweep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/134660#M47378</link>
      <description>&lt;P&gt;Hi Kim,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you are correct. I got confused as per other description where it is mentioned that "zone protection is for destination zone".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the clarification.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 15:02:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scan-host-sweep/m-p/134660#M47378</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-27T15:02:24Z</dc:date>
    </item>
  </channel>
</rss>

