<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP OPTIONS Method in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155912#M51212</link>
    <description>&lt;P&gt;The reason is that some traffic matches the signature for this alert. Would need to check details of the signature and traffic to analyze why exactly it matches and if it's a false positive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to ignore this alert just from (or to) few IP addresses make an exception in that IPS profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to&amp;nbsp;ignore this alert for all traffic make a rule in IPS profile which sets this signature to allow&lt;/P&gt;</description>
    <pubDate>Wed, 10 May 2017 07:22:12 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2017-05-10T07:22:12Z</dc:date>
    <item>
      <title>HTTP OPTIONS Method</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155902#M51211</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am getting contionous 'HTTP OPTIONS Method' - alert&lt;BR /&gt;What is the reason for this&lt;/P&gt;&lt;P&gt;If I have multiple vulnerabilty profile ,I want to exclude this from one of the profile or one of the ip&lt;BR /&gt;(I want to ignore this vulnerabilty checking in a profile or against an IP)&lt;BR /&gt;How can i do that ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 05:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155902#M51211</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-10T05:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP OPTIONS Method</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155912#M51212</link>
      <description>&lt;P&gt;The reason is that some traffic matches the signature for this alert. Would need to check details of the signature and traffic to analyze why exactly it matches and if it's a false positive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to ignore this alert just from (or to) few IP addresses make an exception in that IPS profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to&amp;nbsp;ignore this alert for all traffic make a rule in IPS profile which sets this signature to allow&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 07:22:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155912#M51212</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-05-10T07:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP OPTIONS Method</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155925#M51216</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The reason is that some traffic matches the signature for this alert. Would need to check details of the signature and traffic to analyze why exactly it matches and if it's a false positive.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How to begin the analyziz&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2)I believe there are two ways we can do the exception&lt;BR /&gt;One from under monitor-threats&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vulnerabilty exception.JPG" style="width: 591px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9191i1B466587B390C8E2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vulnerabilty exception.JPG" alt="vulnerabilty exception.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;second from profiles&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vulnerabilty exception-2.JPG" style="width: 786px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9192i905417735AE3B022/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vulnerabilty exception-2.JPG" alt="vulnerabilty exception-2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please correct me if i wrong ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you want to&amp;nbsp;ignore this alert for all traffic make a rule in IPS profile which sets this signature to allow?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;can you expalin this&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 08:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155925#M51216</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-05-10T08:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP OPTIONS Method</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155946#M51220</link>
      <description>&lt;P&gt;For analysis: read the signature description, capture the traffic, see if the destination server is vulnerable etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both ways to exempt IP address are equivalent. From threat monitor is just a shortct to exemptions in IPS profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can make a rule which includes just this signature and set it to allow (like there are rules for other signatures, usualy defined by sevirity). It's same as make an exception just for this signature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 12:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-options-method/m-p/155946#M51220</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-05-10T12:07:44Z</dc:date>
    </item>
  </channel>
</rss>

