<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Brute Force and IP exception in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-brute-force-and-ip-exception/m-p/165796#M53224</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30703"&gt;@Sly_Cooper&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;How exactly did you setup your IP address exemption, can you post a screenshot of that. It's pretty common to get this type of thing messed up and it's not exactly intuative on the GUI. The following article is pretty good at explaining how threat exemptions actually work; it doesn't really work how one would logically think it would.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Add-a-Vulnerability-Exception-to-block-Specifically-Based-Upon/ta-p/66064" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Add-a-Vulnerability-Exception-to-block-Specifically-Based-Upon/ta-p/66064&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jul 2017 12:43:16 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-07-11T12:43:16Z</dc:date>
    <item>
      <title>SSH Brute Force and IP exception</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-brute-force-and-ip-exception/m-p/165667#M53209</link>
      <description>&lt;P&gt;I have vulnerability profile with action for High severity signatures as "alert". &amp;nbsp;I then configured an exception for SSH Brute Force (ID 40015) as "block-ip,&amp;nbsp;src and dst (30 mins)". Everything worked well until we had issues for the systems exiting from our own network and we had to provide an exception for our egress ip. We then added IP address exception under the signature matching our egress ip. Post this the signature stopped blocking SSH brute force attempts for rest of the world. Can someone please help me understand behavior of IP exception in this case? I need SSH brute force signature work for all ip&amp;nbsp;addresses except my company's egress ip.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 21:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-brute-force-and-ip-exception/m-p/165667#M53209</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2017-07-10T21:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Brute Force and IP exception</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-brute-force-and-ip-exception/m-p/165796#M53224</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30703"&gt;@Sly_Cooper&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;How exactly did you setup your IP address exemption, can you post a screenshot of that. It's pretty common to get this type of thing messed up and it's not exactly intuative on the GUI. The following article is pretty good at explaining how threat exemptions actually work; it doesn't really work how one would logically think it would.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Add-a-Vulnerability-Exception-to-block-Specifically-Based-Upon/ta-p/66064" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Add-a-Vulnerability-Exception-to-block-Specifically-Based-Upon/ta-p/66064&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 12:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-brute-force-and-ip-exception/m-p/165796#M53224</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-11T12:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Brute Force and IP exception</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-brute-force-and-ip-exception/m-p/167032#M53413</link>
      <description>&lt;P&gt;Isnt&amp;nbsp;exception reverse of main action? Our threat profiles are configured with category High (server and client) as "Alert". We then configure exception for High&amp;nbsp;severity signatures under Exception by "Enabling" particular signature and action as "reset, drop" etc. So basically I want this exception to have IP exempt for my egress ip&amp;nbsp;address to NOT block. I think my logic is reverse and IP exempt is going to block the ip&amp;nbsp;instead of providing exception?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 17:46:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-brute-force-and-ip-exception/m-p/167032#M53413</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2017-07-18T17:46:55Z</dc:date>
    </item>
  </channel>
</rss>

