<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking action with Virus Threat, but can't find information in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8194#M6057</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this issue went after an AV and threat definition update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Mar 2010 11:21:17 GMT</pubDate>
    <dc:creator>aveva_palo</dc:creator>
    <dc:date>2010-03-26T11:21:17Z</dc:date>
    <item>
      <title>Blocking action with Virus Threat, but can't find information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8192#M6055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a user trying to access a website webinar and they are getting blocked with AV threat name Trojan/Js.Iframe.bgw ID: 259252.&amp;nbsp; The details are as follows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="list"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Log&lt;/TD&gt;&lt;TD class="dashboard"&gt;THREAT&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Type&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;virus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Receive Time&lt;/TD&gt;&lt;TD class="dashboard"&gt;2010/03/22 14:03:23&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Generation Time&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;2010/03/22 14:03:17&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Threat Name&lt;/TD&gt;&lt;TD class="dashboard"&gt;Trojan/Js.Iframe.bgw&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Threat ID&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;259252&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Direction&lt;/TD&gt;&lt;TD class="dashboard"&gt;server-to-client&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;From Zone&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;FW_UplinkOutsid&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;To Zone&lt;/TD&gt;&lt;TD class="dashboard"&gt;FW_UplinkInside&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Attacker&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;4.53.17.200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Victim&lt;/TD&gt;&lt;TD class="dashboard"&gt;10.0.99.20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;From User&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;To User&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;From Port&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;To Port&lt;/TD&gt;&lt;TD class="dashboard"&gt;3376&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Protocol&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;tcp&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Application&lt;/TD&gt;&lt;TD class="dashboard"&gt;web-browsing&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Action&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;deny&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Severity&lt;/TD&gt;&lt;TD class="dashboard"&gt;medium&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Rule&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;Internet&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Ingress I/F&lt;/TD&gt;&lt;TD class="dashboard"&gt;ethernet1/5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Egress I/F&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;ethernet1/6&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Log Action&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Virtual System&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;vsys3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Session Id&lt;/TD&gt;&lt;TD class="dashboard"&gt;461655&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Count&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Configuration Version&lt;/TD&gt;&lt;TD class="dashboard"&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Category&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;any&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Others&lt;/TD&gt;&lt;TD class="dashboard"&gt;hpbroadband.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;SSL Decrypted&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;NAT Applied&lt;/TD&gt;&lt;TD class="dashboard"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Packet Capture&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Captive Portal&lt;/TD&gt;&lt;TD class="dashboard"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Proxy Transaction&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Serial #&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 14:33:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8192#M6055</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2010-03-22T14:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking action with Virus Threat, but can't find information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8193#M6056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you think this is a false positive you can set an exception for this by simply clicking on the threat name from the threat log, then click on "show" next to exceptions, the click on "add".&lt;/P&gt;&lt;P&gt;To pursue this further you will need to call into support so we can take look at this and perhaps refer this to engineering to correct our content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Mar 2010 19:37:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8193#M6056</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-03-23T19:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking action with Virus Threat, but can't find information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8194#M6057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this issue went after an AV and threat definition update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Mar 2010 11:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8194#M6057</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2010-03-26T11:21:17Z</dc:date>
    </item>
  </channel>
</rss>

