<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Same vulnerability profile for dns and web servers security policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/205838#M60413</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply. Sorry for late for coming back to this discussion.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you mean, regardless of the application, the session is scanned for all vulerability signatures by content engine? Its not like if application is identified as DNS then only DNS specific sigantures are checked against the session?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Mar 2018 07:31:41 GMT</pubDate>
    <dc:creator>faizankhurshid</dc:creator>
    <dc:date>2018-03-16T07:31:41Z</dc:date>
    <item>
      <title>Same vulnerability profile for dns and web servers security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/202167#M59668</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering, firewall does not have the option to make vulnerability protection profiles based on signature categories like vulnerability signatures for dns server and web server and then used them in security policies realted to dns only or web server only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in firewall, I can see I&amp;nbsp;have just only one vulnerability protection profile and use in all polices either its for dns or web server. Is there any performance impact for this?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 14:25:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/202167#M59668</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-02-25T14:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Same vulnerability profile for dns and web servers security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/202233#M59678</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The kind of application your profile touches is controlled by the security policy, but the content scanning process is the same for all your sessions. (the presense of a profile sends the packets to the content scanning engine and it will scan the session appropriately)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The security profiles control the decission making process (alert, drop, block ip, ...) but not how the applications are scanned&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 09:39:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/202233#M59678</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-26T09:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Same vulnerability profile for dns and web servers security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/205838#M60413</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply. Sorry for late for coming back to this discussion.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you mean, regardless of the application, the session is scanned for all vulerability signatures by content engine? Its not like if application is identified as DNS then only DNS specific sigantures are checked against the session?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 07:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/205838#M60413</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-16T07:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Same vulnerability profile for dns and web servers security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/205860#M60415</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The packet is handed over to the content scanning engine and it will inspect the packet as efficiently as possible,&amp;nbsp;it uses protocol specific decoders, so if dns is detected it will be inspected by the dns decoder, if http is detected, it will be processed by the http decoder&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 08:05:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/205860#M60415</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-16T08:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Same vulnerability profile for dns and web servers security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/206115#M60505</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just last thing, if decoder is identified as DNS then still it will inspect all vulnerability signatures right?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 08:04:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/206115#M60505</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-17T08:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: Same vulnerability profile for dns and web servers security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/206274#M60538</link>
      <description>&lt;P&gt;yes, for dns related vulnerabilities&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 10:09:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/206274#M60538</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-19T10:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Same vulnerability profile for dns and web servers security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/207343#M60787</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;I also observed for the application unknown-tcp, all vulnerabilities were checked in logs like IIS realted etc&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 07:49:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/207343#M60787</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-26T07:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Same vulnerability profile for dns and web servers security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/207364#M60793</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unknown-tcp does not have a decoder (because it is unknown) so is checked for all vulnerabilities&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 09:30:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-vulnerability-profile-for-dns-and-web-servers-security/m-p/207364#M60793</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-26T09:30:22Z</dc:date>
    </item>
  </channel>
</rss>

