<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block traceroute in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298381#M78197</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I do not think that is possible. However you can just have a policy that explicitly denies the application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2019 23:09:01 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-11-13T23:09:01Z</dc:date>
    <item>
      <title>Block traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/297941#M78128</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;is there a way to block IP source if I match traceroute App-ID? Maybe with a custom vulnerability?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 16:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/297941#M78128</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2019-11-12T16:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Block traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298180#M78161</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure I completely understand the question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you block a source IP using traceroute app-id?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can create a policy to deny traceroute from a source IP, yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is that your question?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 06:18:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298180#M78161</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-13T06:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Block traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298311#M78185</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;no, I want to block IP not deny like in reconnaissance in zone protection or in vulnerability protection that you can create a custom rule with 3600 seconds block IP.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 17:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298311#M78185</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2019-11-13T17:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Block traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298313#M78186</link>
      <description>&lt;P&gt;I appreciate the response.&lt;/P&gt;&lt;P&gt;Maybe I do not understand; deny and block provide similar functionality&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My original response of creating a rule to drop/deny a Source Address is probably the best way to block the IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not being argumentative, perhaps explaining more additional details regarding the use case for this request, will be help everyone to provide better responses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 17:56:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298313#M78186</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-13T17:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Block traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298381#M78197</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I do not think that is possible. However you can just have a policy that explicitly denies the application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 23:09:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298381#M78197</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-11-13T23:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Block traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298383#M78199</link>
      <description>&lt;P&gt;Ill toss in that configuring ICMP error in Zone Protection can help limit the use of Trace-route.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 23:16:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298383#M78199</guid>
      <dc:creator>pteixeira</dc:creator>
      <dc:date>2019-11-13T23:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Block traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298558#M78224</link>
      <description>&lt;P&gt;I want to consider that if an IP make traceroute, this is the first step to do other bad activities on my infrastructure so I want to block it (and not deny) before it can attempt to infiltrate in my network.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 15:30:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298558#M78224</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2019-11-14T15:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Block traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298562#M78225</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;While I agree this could be a start to bad things, its a common tool used by many different engineers. I high caution you against a block-ip approach as this will block legit traffic to/from a good host because someone ran a command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a deny rule is much better in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 15:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-traceroute/m-p/298562#M78225</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-11-14T15:42:09Z</dc:date>
    </item>
  </channel>
</rss>

