<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: antivirus block action for mail protocols in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10686#M7870</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the firewall detects a virus or spyware in SMTP, a 541 response is sent to the sending SMTP server to indicate that the message was rejected. This allows the Palo Alto Networks firewall to effectively block viruses distributed over SMTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For POP3/IMAP, the only action the firewall will ever take is “alert”. The device will never block or drop for these protocols, even if you configure an action of “block”.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Aug 2013 09:22:34 GMT</pubDate>
    <dc:creator>harshanatarajan</dc:creator>
    <dc:date>2013-08-08T09:22:34Z</dc:date>
    <item>
      <title>antivirus block action for mail protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10684#M7868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at a customer's location we have a PA for evaluation. Now we found that 2 viruses have been reported via SMTP. The AV policy was set to block for smtp. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the question is, how has this been treated. In the ACE exam there was the correct answer that it only alerts even if it set to block, but maybe this has changed in panos 5.0.6? Would be great to know, if the customer has a virus we could disinfect as a service or that the PA successfully defended the "holy grounds" &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 09:13:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10684#M7868</guid>
      <dc:creator>vertical</dc:creator>
      <dc:date>2013-08-08T09:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: antivirus block action for mail protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10685#M7869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alert is just log the alert but do not block&lt;/P&gt;&lt;P&gt;Block is log the alert an block the stream.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 09:20:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10685#M7869</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-08-08T09:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: antivirus block action for mail protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10686#M7870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the firewall detects a virus or spyware in SMTP, a 541 response is sent to the sending SMTP server to indicate that the message was rejected. This allows the Palo Alto Networks firewall to effectively block viruses distributed over SMTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For POP3/IMAP, the only action the firewall will ever take is “alert”. The device will never block or drop for these protocols, even if you configure an action of “block”.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 09:22:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10686#M7870</guid>
      <dc:creator>harshanatarajan</dc:creator>
      <dc:date>2013-08-08T09:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: antivirus block action for mail protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10687#M7871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for that &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 09:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10687#M7871</guid>
      <dc:creator>vertical</dc:creator>
      <dc:date>2013-08-08T09:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: antivirus block action for mail protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10688#M7872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just saw this threat because it was referenced in another Threat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"For POP3/IMAP, the only action the firewall will ever take is “alert”. The device will never block or drop for these protocols, even if you configure an action of “block”."&lt;/P&gt;&lt;P&gt;--&amp;gt; This is not correct.&lt;/P&gt;&lt;P&gt;If you set "block" Action the PA will terminate (Reset) a Session is a Virus is found in Pop3/IMAP.&lt;/P&gt;&lt;P&gt;Be aware that you will not be able to get any new Mail from this Server until you delete the Virus on Server Site.&lt;/P&gt;&lt;P&gt;(Because everytime your Client requests new Mails your whole Session to the Server will be reset, not only the one with the Virus in it)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2014 09:13:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-block-action-for-mail-protocols/m-p/10688#M7872</guid>
      <dc:creator>MarcoLeckel</dc:creator>
      <dc:date>2014-12-15T09:13:32Z</dc:date>
    </item>
  </channel>
</rss>

