<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Antivirus/Anti-Spyware Response Page not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/254163#M72150</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same behavior, response pages for unencryped flows are working, response pages for encrypted (with SSL interception) app + URL filtering are also working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However other encrypted flows (with SSL interception) like AV, vulnerability are not working but I think it's by designed for the transparent proxy:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does someone know a way to change the behavior even if it's not a proper response page but something that may challenge the user that the firewall is blocking something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2019 08:53:07 GMT</pubDate>
    <dc:creator>kasito</dc:creator>
    <dc:date>2019-03-19T08:53:07Z</dc:date>
    <item>
      <title>Antivirus/Anti-Spyware Response Page not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/138523#M47977</link>
      <description>&lt;P&gt;Hey Community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed that our Firewall (PA-3020, PAN-OS 7.1.6) does not serve an Antivirus/Anti-Spyware block page.&lt;/P&gt;&lt;P&gt;When I use &lt;A href="http://www.eicar.org/85-0-Download.html" target="_blank"&gt;http://www.eicar.org/85-0-Download.html&lt;/A&gt; to test it, I can see that it is blocked.&lt;/P&gt;&lt;P&gt;ThreatLog shows action "reset-both" but in the Browser (tested with Firefox 50.1.0 and IE 11 11.576.14393.0/Win10) I don´t get the desired and configured Block-Page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;URL-Filter and Application block pages are working as expected, but AV/Spyware block page is not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSL-Decryption is enabled and if I use&amp;nbsp;&lt;A href="https://secure.eicar.org/eicar.com" target="_blank"&gt;https://secure.eicar.org/eicar.com&lt;/A&gt; for download, the download is also blocked, but I don´t get a block page. So no matter if http or https is used, the file is blocked but no response page is served.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also have a PA-500 - PAN-OS 7.1.6, no&amp;nbsp; SSL-Decryption active - response pages are configured and I get the same result as on our PA-3020, that is: URL-Filter and Application block pages are working as expected, but AV/Spyware block page is not served to the client browser, although the download is blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone else have the similar issues?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Alex.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 09:51:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/138523#M47977</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2017-01-20T09:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus/Anti-Spyware Response Page not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/138557#M47984</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;short question, do you enable response page in Device / Response page ?&lt;/P&gt;&lt;P&gt;look:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/device/device-response-pages" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/device/device-response-pages&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For SSL:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-an-HTTPS-Session-Without/ta-p/55998" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-an-HTTPS-Session-Without/ta-p/55998&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 13:25:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/138557#M47984</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2017-01-20T13:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus/Anti-Spyware Response Page not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/138563#M47986</link>
      <description>&lt;BR /&gt;Thanks VinceM,&lt;BR /&gt;but as far as I know, you can't enable nor disable AV-Response page. At least there is no option for doing that.&lt;BR /&gt;Application response page is enabled and as I mentioned in my original post, App and Url response pages or working correctly.&lt;BR /&gt;&lt;BR /&gt;The following command is set - required for SSL decrypt.&lt;BR /&gt;set deviceconfig setting url dynamic-url yes&lt;BR /&gt;&lt;BR /&gt;the managment profile for the egress interface is set to enable response pages.&lt;BR /&gt;I know for sure, that the AV response page worked when we first implemented the firewall 3 years ago and I think that was on&lt;BR /&gt;PAN-OS 5.X&lt;BR /&gt;I don't know when it stopped working &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Alex.</description>
      <pubDate>Fri, 20 Jan 2017 14:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/138563#M47986</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2017-01-20T14:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus/Anti-Spyware Response Page not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/254163#M72150</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same behavior, response pages for unencryped flows are working, response pages for encrypted (with SSL interception) app + URL filtering are also working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However other encrypted flows (with SSL interception) like AV, vulnerability are not working but I think it's by designed for the transparent proxy:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does someone know a way to change the behavior even if it's not a proper response page but something that may challenge the user that the firewall is blocking something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 08:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-anti-spyware-response-page-not-working/m-p/254163#M72150</guid>
      <dc:creator>kasito</dc:creator>
      <dc:date>2019-03-19T08:53:07Z</dc:date>
    </item>
  </channel>
</rss>

