<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone protection for scan up / ports from internet ( untrust) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301753#M78706</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105755"&gt;@AudioCodes&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you actually toned it for your environment. The thing with ZPP is that they need to be customized to your environment; the defaults won't do you any good.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Dec 2019 21:38:23 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-12-02T21:38:23Z</dc:date>
    <item>
      <title>Zone protection for scan up / ports from internet ( untrust)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301528#M78683</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi ,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyone enable zone protection for protect and drop scan ip and ports from untrust / internet to DMZ or untrust ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i enabled it but I have alerts only from DMZ to untrust and not from untrust to DMZ or untrust to untrust.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2019 19:17:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301528#M78683</guid>
      <dc:creator>AudioCodes</dc:creator>
      <dc:date>2019-12-01T19:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection for scan up / ports from internet ( untrust)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301753#M78706</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105755"&gt;@AudioCodes&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you actually toned it for your environment. The thing with ZPP is that they need to be customized to your environment; the defaults won't do you any good.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 21:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301753#M78706</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-02T21:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection for scan up / ports from internet ( untrust)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301800#M78718</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you determine the right settings, are there general guidelines or some reference available?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 02:07:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301800#M78718</guid>
      <dc:creator>BruceBennett</dc:creator>
      <dc:date>2019-12-03T02:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection for scan up / ports from internet ( untrust)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301801#M78719</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43551"&gt;@BruceBennett&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;When it comes to flood protection you need to adjust the alarm rate based off of the information you can gather through a netflow capture, or you can simply take a guess and adjust as needed. Just ensure that you are only lowering the alarm rate and not the activate and maximum values and you'll only trigger a log when that rate is hit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Reconnaissance Protection you can set the action to alert and mess around with the interval/threshold value as you see fit. Again, as long as it is only set to alert no negative action will take place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 02:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-for-scan-up-ports-from-internet-untrust/m-p/301801#M78719</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-03T02:44:20Z</dc:date>
    </item>
  </channel>
</rss>

