<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 8.1.2 file-blocking / logging traffic direction in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/221135#M63720</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;gwesson for the detailed description.&lt;/P&gt;&lt;P&gt;I will have a deeper look into it at different Pan-OS versions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jul 2018 07:22:14 GMT</pubDate>
    <dc:creator>ABux</dc:creator>
    <dc:date>2018-07-09T07:22:14Z</dc:date>
    <item>
      <title>8.1.2 file-blocking / logging traffic direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/220345#M63570</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after updating from 8.0.x to 8.1.2 we noticed the following behaviour:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Data Filtering Monitor the direction of the traffic has moved.&lt;/P&gt;&lt;P&gt;Connections previously shown as 'from internt to lan' are now shown as 'from lan to internet'.&lt;/P&gt;&lt;P&gt;This when downloading a file.&lt;/P&gt;&lt;P&gt;A colleague just remembered that there was a notice that all traffic logs will be changed to be in the same order.&lt;/P&gt;&lt;P&gt;But I did not find this in the release notes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a file blocking profile configured to the internet policy which matches my connection.&lt;/P&gt;&lt;P&gt;This policy will deny uploads and allow downloads.&lt;/P&gt;&lt;P&gt;But after the update the download is blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it looks like the logging of the traffic was changed but these direction will not be noticed for file blocking correctly.&lt;/P&gt;&lt;P&gt;Does anyone notice a similar problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sorry I can not test if the upload is working now, instead.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Andi&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 13:28:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/220345#M63570</guid>
      <dc:creator>ABux</dc:creator>
      <dc:date>2018-07-03T13:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.2 file-blocking / logging traffic direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/220779#M63649</link>
      <description>&lt;P&gt;You're correct, there was a change in 8.1 for the directionality, but I also cannot find any specific documentation on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The direction of certain logs was purposefully altered in 8.0 and older to help readability for logs like Threat and Data. The "source" and "destination" fields are changed to "Attacker" and "Victim", and because the victim is generally the user (not the external web server) that swap makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a good article discussing it:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Threat-Logs-Show-Inverted-Reversed-Direction-for-Source-and/ta-p/55493" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Threat-Logs-Show-Inverted-Reversed-Direction-for-Source-and/ta-p/55493&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem was that in 8.0 the Unified Logs page was added, allowing admins to review all the different logs in one place. When the Threat and Data logs were viewed along with the Traffic log, the swapping of addresses loses its context because the Unified Log page only has one field for each IP ("Source address" and "Destination address").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus, 8.1 stops doing that so the Unified Logs don't have a weirdly swapped source/destination ip/port. If you've still got an 8.0 firewall check out the columns in the Threat Log and you'll see Attacker and Victim instead of Source Address and Destination Address.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 22:03:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/220779#M63649</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-07-05T22:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.2 file-blocking / logging traffic direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/220793#M63650</link>
      <description>&lt;P&gt;Thanks for the additional detail&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203"&gt;@gwesson&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've historically used log filters such as (addr in x.x.x.x) in the unified log.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That way, it catches any of the logs relating to x.x.x.x either as "source" or "destination"... this includes both uploads &amp;amp; downloads, client/tcp-initiator &amp;amp; server, attacker &amp;amp; victim, etc.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll have to keep an eye out for the changes in 8.1.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 22:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/220793#M63650</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-07-05T22:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.2 file-blocking / logging traffic direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/221135#M63720</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;gwesson for the detailed description.&lt;/P&gt;&lt;P&gt;I will have a deeper look into it at different Pan-OS versions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 07:22:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-2-file-blocking-logging-traffic-direction/m-p/221135#M63720</guid>
      <dc:creator>ABux</dc:creator>
      <dc:date>2018-07-09T07:22:14Z</dc:date>
    </item>
  </channel>
</rss>

