<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA SMB deny behaviour in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188344#M57183</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cap.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12585i687CFF0DF43A1030/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cap.JPG" alt="cap.JPG" /&gt;&lt;/span&gt;This is the session browser right now. I think that the 445-SMB&amp;nbsp; traffic that we are seeing in ISP router is because of threeway-handshake. But how can discard this traffic in order to not see it in ISP??&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2017 14:53:27 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2017-11-22T14:53:27Z</dc:date>
    <item>
      <title>PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188331#M57178</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have detected a atrange behaviour with SMB session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have created a rule for blocking wannacry (SMB) sessions&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura2.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12582i41B8F060CF2646B6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Captura2.JPG" alt="Captura2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can see sessions being blocked:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura3.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12583i4F5F5525728F077D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Captura3.jpg" alt="Captura3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So all sessions from trust to untrust should be blocked but we have done a tcpdump in our ISP router an we see&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2017-11-21 20:01:46: 8x.x.x.x&amp;nbsp;=&amp;gt; 213.187.106.86:445&lt;BR /&gt;2017-11-21 20:01:46: &lt;SPAN&gt;8x.x.x.x&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;=&amp;gt; 213.187.106.87:445&lt;BR /&gt;2017-11-21 20:01:46: &lt;SPAN&gt;8x.x.x.x&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt; =&amp;gt; 213.187.106.88:445&lt;BR /&gt;2017-11-21 20:01:46: &lt;SPAN&gt;8x.x.x.x&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt; =&amp;gt; 213.187.106.92:445&lt;BR /&gt;2017-11-21 20:01:46: &lt;SPAN&gt;8x.x.x.x&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt; =&amp;gt; 213.187.106.93:445&lt;BR /&gt;2017-11-21 20:01:46: &lt;SPAN&gt;8x.x.x.x&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt; =&amp;gt; 213.187.106.94:445&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why ISP is receiving sessions in port445 to untrust if we have deny all session from inside to outside????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 14:10:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188331#M57178</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-11-22T14:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188338#M57179</link>
      <description>&lt;P&gt;try filtering your policy on&amp;nbsp;"( action neq deny ) and ( port.dst eq 445 )" instead of your rule to see if there's anything allowed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also try one with&amp;nbsp;( addr.dst in&amp;nbsp;&lt;SPAN&gt;213.187.106.86&lt;/SPAN&gt; ) to see if it shows up in any other form&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 14:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188338#M57179</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-22T14:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188339#M57180</link>
      <description>&lt;P&gt;There is not any session being alloweb with neq deny.&lt;/P&gt;&lt;P&gt;I think PA is permitting the 3way handshake to detect the app (so these packets is ahwt we see in ISP router) but we have denied by service, i think PA shouldnt permit 3way handshake.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;using this filter&amp;nbsp;&lt;SPAN&gt;( addr.dst in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;213.187.106.86&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;), we dont see any logs in PA. Weird......&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a bit strange...&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 14:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188339#M57180</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-11-22T14:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188340#M57181</link>
      <description>&lt;P&gt;No, the 3way handshake is alowed through if you have a policy that includes applications. You have 'any' so the action is applied on the port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible the connection could have originated from a different source zone? (the policy is only for trust). Could someone have connected a host on the outside network segment?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 14:43:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188340#M57181</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-22T14:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188341#M57182</link>
      <description>&lt;P&gt;ammmmmm, i though that if i block using service 445 the 3way is not done. So how can i do in order to discard all connections in 445, so ISP router wont receive this traffic????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 14:46:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188341#M57182</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-11-22T14:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188344#M57183</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cap.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12585i687CFF0DF43A1030/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cap.JPG" alt="cap.JPG" /&gt;&lt;/span&gt;This is the session browser right now. I think that the 445-SMB&amp;nbsp; traffic that we are seeing in ISP router is because of threeway-handshake. But how can discard this traffic in order to not see it in ISP??&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 14:53:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188344#M57183</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-11-22T14:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188346#M57184</link>
      <description>&lt;P&gt;if you use only ports, 3 way handshake is not allowed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you do a &lt;FONT face="courier new,courier"&gt;&amp;gt; show running security-policy&lt;/FONT&gt; to verify the policies?&lt;/P&gt;
&lt;P&gt;are the negated subnets necessary? can you try removing them?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 15:24:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188346#M57184</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-22T15:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188350#M57186</link>
      <description>&lt;P&gt;This is the rule by CLI:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Block 445 Wannacry" {&lt;BR /&gt;from trust;&lt;BR /&gt;source any;&lt;BR /&gt;source-region none;&lt;BR /&gt;to untrust;&lt;BR /&gt;destination [ 0.0.0.0/5 8.0.0.0/7 11.0.0.0/8 12.0.0.0/6 16.0.0.0/4 32.0.0.0/3 64.0.0.0/4 80.0.0.0/6&amp;nbsp;];&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service [ any/tcp/any/445 any/udp/any/445 ];&lt;BR /&gt;action deny;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ill create a first rule permiting the traffic in our networks, and below ill create another one denying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read SMBv3 is encrypted, it could be that 3way handshake should be done in order to know app????&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 16:41:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188350#M57186</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-11-22T16:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188352#M57187</link>
      <description>&lt;P&gt;the 3 way handshake&amp;nbsp;is NOT allowed in this particular rule because you have 'any' in the application , 2 ports and deny. this means any packet matching destination port 445 will be dropped&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it IS possible (since this is rule #3, the 3 way handshake is being allowed by rule #1 or #2 (if they allow port 445 and have an (different) application, because then we DO allow the handshake to be able to identify the application)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so maybe this rule needs to move up to #1&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 15:49:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188352#M57187</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-22T15:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188354#M57188</link>
      <description>&lt;P&gt;Exactly, that what i think. Three-way is not enabled filtering by service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rules 1 y 2 are deployed by panorama, and the sources are&amp;nbsp;specific hosts. So it shouldnt be the problem......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cappp.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12588iD9A575EE4FEA02A9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cappp.jpg" alt="cappp.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 15:56:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188354#M57188</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-11-22T15:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188356#M57190</link>
      <description>&lt;P&gt;I tried to create a first rule permitting, and second one denying, but the problem is the same. 3way is done.&lt;/P&gt;&lt;P&gt;I have replicated this problem i my lab in version 8.0.5 and 3way is done fitlering by port &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;it seems like normal behaviour in PA. Can someone confirm if you create a rule denying port 445, the 3way is done??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks alot&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 16:37:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188356#M57190</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-11-22T16:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188358#M57191</link>
      <description>&lt;P&gt;Ok I will admit this is weird&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you try setting up a flow basic to see what is happening exactly ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 16:37:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188358#M57191</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-22T16:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188359#M57192</link>
      <description>&lt;P&gt;Hi reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I replicated the problem in my lab.&amp;nbsp;I created a rule denying port 445 sessions and i can see this traffic in logs. It seems like 3way is done using SMB althoug you are denying by port445.&lt;/P&gt;&lt;P&gt;it seems like a bug or normal behaviour PA.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 16:41:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188359#M57192</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-11-22T16:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: PA SMB deny behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188501#M57203</link>
      <description>&lt;P&gt;I've also reproduced and I am not able to reproduce your issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BUT!, I think i may have found the issue... this is my policy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12597i68257B1F2FEEAA7A/image-size/large?v=v2&amp;amp;px=999" role="button" title="policy.png" alt="policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may notice I used 'drop' and I'm getting all my 445 discarded as expected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you used 'Deny'&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="deny vs drop.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12598i529E73EECE711E21/image-size/large?v=v2&amp;amp;px=999" role="button" title="deny vs drop.png" alt="deny vs drop.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deny requires an application to decide the appropriate 'reject' action for the application&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you need to actively reject i'd propose you use 'Reset Client' instead&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 09:44:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-smb-deny-behaviour/m-p/188501#M57203</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-23T09:44:08Z</dc:date>
    </item>
  </channel>
</rss>

