<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama and Scan Type threats in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154882#M50978</link>
    <description>&lt;P&gt;those versions should not be an issue&lt;/P&gt;
&lt;P&gt;is there a difference between all the profiles? if they're all identical (ecept for the severity filter) it might be better to combine them all into one profile.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 May 2017 16:16:26 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-05-02T16:16:26Z</dc:date>
    <item>
      <title>Panorama and Scan Type threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154857#M50973</link>
      <description>&lt;P&gt;Anyone know if Panorama is supposed to show Scan type threats in the Threats or Unified views under Monitoring? &amp;nbsp;I'm investigating why some of our Autodesk software on campus is having problems reaching the licensing server... Panorama didn't show any problems and I can see allowed traffic but then noticed drops in a packet capture. &amp;nbsp;Checking the Threats on the individual firewalls showed a number of "SCAN: TCP Port Scan" with the action "block-ip".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also not sure how I'm getting block-IP here. &amp;nbsp;That may it's default action but the Vulnerability Protection profile I have applied to that security policy should just alert on Medium or lower and the scan threat it is identifying is classified as Medium.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 15:21:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154857#M50973</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-05-02T15:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama and Scan Type threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154872#M50974</link>
      <description>&lt;P&gt;that's a zone protection action rather than a threat prevention signature&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zone protetion.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/5DE745A4213343D2E26844B0146B285E/responsive_peak/images/image_not_found.png" alt="zone protetion.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;they get added to the system log, so you probably don't have log forwarding enabled for system logs&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panorama forwarding.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/5DE745A4213343D2E26844B0146B285E/responsive_peak/images/image_not_found.png" alt="panorama forwarding.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 15:51:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154872#M50974</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-05-02T15:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama and Scan Type threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154873#M50975</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok I see that now in Zone protection, however I have System logs already set to forward to Panorama. &amp;nbsp;We've actually got them split out for some reason... instead of "All Logs" we have one fore each severity level but every one of them has Panorama checked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possibly due to a version difference? &amp;nbsp;We're running Panorama 8.0.1 and 7.1.8 on the firewalls.&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 15:58:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154873#M50975</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-05-02T15:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama and Scan Type threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154882#M50978</link>
      <description>&lt;P&gt;those versions should not be an issue&lt;/P&gt;
&lt;P&gt;is there a difference between all the profiles? if they're all identical (ecept for the severity filter) it might be better to combine them all into one profile.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 16:16:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154882#M50978</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-05-02T16:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama and Scan Type threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154887#M50981</link>
      <description>&lt;P&gt;I believe the only difference is the severity filter. &amp;nbsp;I don't recall setting it up that way but I don't see why I shouldn't be able to just change it to All Logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We may have just solved the overall problem by telling the client Autodesk software's config to use a specific port which seems to prevent the application from initiating a port scan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I definitely want to get those logs showing up on Panorama though... having an incomplete picture without going to the firewalls kind of defeats the purpose.&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 17:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-and-scan-type-threats/m-p/154887#M50981</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-05-02T17:17:39Z</dc:date>
    </item>
  </channel>
</rss>

