<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: excluding threats from TAP allerting? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/216235#M62647</link>
    <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am now not getting bombarded by unwanted alerts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jun 2018 09:17:38 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2018-06-01T09:17:38Z</dc:date>
    <item>
      <title>excluding threats from TAP allerting?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/215290#M62480</link>
      <description>&lt;P&gt;We have a TAP interface listening to a number of vlans (internal and external)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We get a lot of noise in our allerts from threats we would prefer not to get alerted on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, presently "SipVicious"&amp;nbsp; scans are occuring all the time to what are actually unused IP addresses on one VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we dial these out???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 07:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/215290#M62480</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-05-24T07:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: excluding threats from TAP allerting?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/215360#M62489</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I imagine if you are using a TAP interface you are just in the process of actually getting all of this setup, and therefore likely using the default profiles. This will by default cause an alert to be generated, but if you use a profile other than the default you can actually build out an exclusion within the profile to ignore certain threats.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would be slightly more concerned however that you are getting alerts for scans taking place on the tap interface. Have you properly investigated these and verified that there aren't actually scans taking place across your network for some reason? If it's a false positive then I would look at adding an exclusion into the profile if you truly want to just get rid of the alerts that are being generated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's all of the IDs that you would need to exclude from a Spyware profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15262i2C5E59E93D3B06B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 16:01:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/215360#M62489</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-24T16:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: excluding threats from TAP allerting?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/215480#M62498</link>
      <description>&lt;P&gt;I do have Specific profiles for the Tap for (AV/AS/VP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And on the AS profile where SIPVicious can be found I have added an exclusion,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So "SIPVicious" is on the Anti-Spyware profile, I have a exclusion for the "Audit-Tool" as that's the only one we see.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the alerts still come though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ips.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15298iFB98F7EA833D7171/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ips.jpg" alt="ips.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This particular traffic is on the outside of the network, it's being picked up as there is an un-routed&amp;nbsp;"VLAN" on one of the monitored switch ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we also get a lot of alerts generated because we run our own internal vulnerability scanner, so we generate our own false positive results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 08:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/215480#M62498</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-05-25T08:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: excluding threats from TAP allerting?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/216107#M62619</link>
      <description>&lt;P&gt;In this exception you have action 'drop'. That will always be logged. Change to allow in exception.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 13:15:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/216107#M62619</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-05-31T13:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: excluding threats from TAP allerting?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/216117#M62625</link>
      <description>&lt;P&gt;Ah right, will give that a go, althought the scans for that particular threat appear to have stopped now anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 15:48:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/216117#M62625</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-05-31T15:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: excluding threats from TAP allerting?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/216235#M62647</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am now not getting bombarded by unwanted alerts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 09:17:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/excluding-threats-from-tap-allerting/m-p/216235#M62647</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-06-01T09:17:38Z</dc:date>
    </item>
  </channel>
</rss>

