<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 485-2569 Dynamic Updates issue? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9494#M6970</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may have seen already, but PA are advising that we should roll back to 484.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Feb 2015 09:12:43 GMT</pubDate>
    <dc:creator>DavePalo</dc:creator>
    <dc:date>2015-02-12T09:12:43Z</dc:date>
    <item>
      <title>485-2569 Dynamic Updates issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9491#M6967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone noting a large increase in triggering of following threat ID's after this Update (485-2569) was applied? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;( threatid eq 36485 ) - &lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ebedee;"&gt;OpenSSL SSL/TLS MITM vulnerability&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;( threatid eq 36420 ) - &lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ebedee;"&gt;OpenSSL TLS Heartbeat Information Disclosure Vulnerability - Reverse Heartbleed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've rolled it back as it was dropping a lot of HTTPS traffic for sites that looked ok on closer inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is mainly for internal users connecting to external sites out of our control for the first threat ( 36485 ).&lt;/P&gt;&lt;P&gt;The reverse ones (&lt;SPAN style="font-size: 13.3333330154419px;"&gt;36420) &lt;/SPAN&gt; i'm not so worried about as they are probably dodgy sites to begin with.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2015 02:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9491#M6967</guid>
      <dc:creator>paul.stinson</dc:creator>
      <dc:date>2015-02-11T02:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: 485-2569 Dynamic Updates issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9492#M6968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can take captures for those threat packets and open up a case.&lt;/P&gt;&lt;P&gt;Please refer: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-2769"&gt;How to Submit a Virus/Vulnerability False Positive&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hitesh Mistry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2015 18:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9492#M6968</guid>
      <dc:creator>hmistry</dc:creator>
      <dc:date>2015-02-11T18:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: 485-2569 Dynamic Updates issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9493#M6969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having the same thing on my site.&amp;nbsp; 100's of alerts coming from untrust-&amp;gt; our DMZ, there have been a 5 or 6 of the OpenSSL MITM from internal - untrust.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The updated installed last night at 3am on our boxes and alerts started at 3:08am.&amp;nbsp; Reverting back for now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2015 20:05:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9493#M6969</guid>
      <dc:creator>tom.mccomb</dc:creator>
      <dc:date>2015-02-11T20:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: 485-2569 Dynamic Updates issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9494#M6970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may have seen already, but PA are advising that we should roll back to 484.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2015 09:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9494#M6970</guid>
      <dc:creator>DavePalo</dc:creator>
      <dc:date>2015-02-12T09:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: 485-2569 Dynamic Updates issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9495#M6971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Palo Alto Networks has determined that Application and Threat Content version 485 may introduce false-positive triggers on certain IPS signatures involving SSL changes in that content release. We removed content release 485 from public update servers and are re-releasing Application and Threat Content 486 with the SSL changes removed. Please be informed that now content 486 is available.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2015 09:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/485-2569-dynamic-updates-issue/m-p/9495#M6971</guid>
      <dc:creator>gbogojevic</dc:creator>
      <dc:date>2015-02-12T09:20:58Z</dc:date>
    </item>
  </channel>
</rss>

