<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Opened session remains after threat triggered block-ip. WTF! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/opened-session-remains-after-threat-triggered-block-ip-wtf/m-p/142109#M48490</link>
    <description>&lt;P&gt;Hi, I've been testing the block-ip action in spyware DNS signatures. I was an RDP session before the threat triggered the block-ip action. Then, no more connections are allowed (what is OK), but the RDP session remains open.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a normal behaviour? I think the FW should reset all the sessions previosly established for the blocked IP, shouldn't it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2017 13:07:31 GMT</pubDate>
    <dc:creator>ACortes</dc:creator>
    <dc:date>2017-02-09T13:07:31Z</dc:date>
    <item>
      <title>Opened session remains after threat triggered block-ip. WTF!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/opened-session-remains-after-threat-triggered-block-ip-wtf/m-p/142109#M48490</link>
      <description>&lt;P&gt;Hi, I've been testing the block-ip action in spyware DNS signatures. I was an RDP session before the threat triggered the block-ip action. Then, no more connections are allowed (what is OK), but the RDP session remains open.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a normal behaviour? I think the FW should reset all the sessions previosly established for the blocked IP, shouldn't it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 13:07:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/opened-session-remains-after-threat-triggered-block-ip-wtf/m-p/142109#M48490</guid>
      <dc:creator>ACortes</dc:creator>
      <dc:date>2017-02-09T13:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Opened session remains after threat triggered block-ip. WTF!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/opened-session-remains-after-threat-triggered-block-ip-wtf/m-p/142135#M48495</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;with the block-ip action set, the malicious session will be terminated and any new sessions will be blocked before they are created, but existing sessions could remain open as they were established before the malicious event.&lt;/P&gt;
&lt;P&gt;scanning on this active session will continue and if any malicious packets are identified in that session, it will also be terminated&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 14:38:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/opened-session-remains-after-threat-triggered-block-ip-wtf/m-p/142135#M48495</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-02-09T14:38:21Z</dc:date>
    </item>
  </channel>
</rss>

