<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat prevention subscription in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8997#M6572</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm glad that I can help You.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course yes I had. This is normal situation - You must consider it. Read this community and You will see from time to time peopleas complaining about updates that was replaced in couples of hours by new version and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 May 2015 12:56:42 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2015-05-06T12:56:42Z</dc:date>
    <item>
      <title>Threat prevention subscription</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8994#M6569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is anyone using the threat prevention subscription and how are they configuring it?&amp;nbsp; I know that there are things I want to block but currently I have only set it to alert. What is the best way to configure the security profiles to get the best result?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 May 2015 13:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8994#M6569</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-05-05T13:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention subscription</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8995#M6570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did You read &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3094" title="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;https://live.paloaltonetworks.com/docs/DOC-3094&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please also think about &lt;A href="https://live.paloaltonetworks.com/palo-blogpost/1156"&gt;Tips &amp;amp;amp; Tricks: Using DNS Sinkhole to find Malicious Clients&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6220"&gt;How to Configure DNS Sinkhole&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and of course &lt;A href="https://live.paloaltonetworks.com/message/51788"&gt;CVE-2015-1635 and SSL decryption - is needed?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Volnureability Ptorection Profile looks like:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-05-06_084113.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19528_2015-05-06_084113.png" style="height: 137px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;and it's atached to security policy that allow users access to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 06:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8995#M6570</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-05-06T06:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention subscription</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8996#M6571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks yes I read that documentation and thanks for sharing the configuration of yours with me. Have you had any issues with blocking false positives&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 12:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8996#M6571</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-05-06T12:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention subscription</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8997#M6572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm glad that I can help You.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course yes I had. This is normal situation - You must consider it. Read this community and You will see from time to time peopleas complaining about updates that was replaced in couples of hours by new version and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 12:56:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8997#M6572</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-05-06T12:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention subscription</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8998#M6573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my experience, I found it easier to configure a more aggressive profile for the DMZ because the traffic is much more predictable than what I see coming from inside the network. I work in a university and students use a lot of applications. Putting the action to alert is a good way to start. Eventually, you will see in the logs what you really want to block.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 13:45:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8998#M6573</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2015-05-06T13:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention subscription</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8999#M6574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I took work at a university haven't really focused on the DMZ just trying to start the testing of the best method to approach the threat prevention. Just curious what In the logs keyed you in on what to block?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 13:53:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/8999#M6574</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-05-06T13:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention subscription</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/9000#M6575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a daily report of all the threats and their repeat count. I focus mostly on the critical and high severity threats, and I tend to spend more time on exploit kits and command and control traffic. I enable packet capture for most threats, so I can more easily find out if it's a false positive or not. I also like to tune the brute-force attack settings to block attackers while letting legitimate users in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2015 02:40:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/9000#M6575</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2015-05-11T02:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Threat prevention subscription</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/9001#M6576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will try that thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2015 12:58:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-subscription/m-p/9001#M6576</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-05-11T12:58:14Z</dc:date>
    </item>
  </channel>
</rss>

