<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question Regarding Reporting in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-reporting/m-p/9342#M6846</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm responsible for Security Analysis at a Telecommunications company up in New England. We've recently deployed Palo Alto firewalls to all sites, and I am currently going through PDF Reports manually while we get Splunk installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing that confuses me is that occasionally, when doing a custom report, we get a traffic action I'm not familiar with. Typically we see 'alert' or 'drop all packets'. However, in one of our sites, we're seeing traffic labeled as 'reset-both' (image below, fifth line. This report is custom, created from the threat logs at this site).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone explain what this action means in comparison to 'drop all packets'? Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Travis Fitzgerald&lt;IMG alt="paquestion.bmp" class="jive-image-thumbnail jive-image" height="290" src="https://live.paloaltonetworks.com/legacyfs/online/6872_paquestion.bmp" style="height: 290px; width: 737.2881355932203px;" width="737" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Jun 2013 13:56:57 GMT</pubDate>
    <dc:creator>tfitzgerald</dc:creator>
    <dc:date>2013-06-11T13:56:57Z</dc:date>
    <item>
      <title>Question Regarding Reporting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-reporting/m-p/9342#M6846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm responsible for Security Analysis at a Telecommunications company up in New England. We've recently deployed Palo Alto firewalls to all sites, and I am currently going through PDF Reports manually while we get Splunk installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing that confuses me is that occasionally, when doing a custom report, we get a traffic action I'm not familiar with. Typically we see 'alert' or 'drop all packets'. However, in one of our sites, we're seeing traffic labeled as 'reset-both' (image below, fifth line. This report is custom, created from the threat logs at this site).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone explain what this action means in comparison to 'drop all packets'? Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Travis Fitzgerald&lt;IMG alt="paquestion.bmp" class="jive-image-thumbnail jive-image" height="290" src="https://live.paloaltonetworks.com/legacyfs/online/6872_paquestion.bmp" style="height: 290px; width: 737.2881355932203px;" width="737" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jun 2013 13:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-reporting/m-p/9342#M6846</guid>
      <dc:creator>tfitzgerald</dc:creator>
      <dc:date>2013-06-11T13:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Question Regarding Reporting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-reporting/m-p/9343#M6847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 12.222222328186035px; background-color: #ffffff;"&gt; Reset-both: When selected as the action on the signature, the firewall will drop the packet and send a TCP reset to both client and server.&amp;nbsp; This action is available in vulnerability protection exceptions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="margin: 0 0 10px; font-style: inherit; font-size: 12.222222328186035px; font-family: inherit;"&gt;&amp;nbsp; Drop-all-Packets: When selected as the action on the signature, the firewall will drop every subsequent packet for that connection.&amp;nbsp; This action is available in vulnerability protection exceptions.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jun 2013 14:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-reporting/m-p/9343#M6847</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2013-06-11T14:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Question Regarding Reporting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-reporting/m-p/9344#M6848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome, thanks. That's just what I needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jun 2013 14:16:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-reporting/m-p/9344#M6848</guid>
      <dc:creator>tfitzgerald</dc:creator>
      <dc:date>2013-06-11T14:16:04Z</dc:date>
    </item>
  </channel>
</rss>

