<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIPVicious Scanner Detection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/360777#M88134</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In your Vulnerability profile, set it to block anything medium and higher. SipVicious used to be low but since I block anything medium and higher, a custom policy is not longer required for me. But you can still block/unblock is with an exception.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1604529614363.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28505i96E95ADCE9CE5B0C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1604529614363.png" alt="OtakarKlier_0-1604529614363.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just change the action to like drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2020 22:40:35 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2020-11-04T22:40:35Z</dc:date>
    <item>
      <title>SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/281908#M76009</link>
      <description>&lt;P&gt;is it just me or anyone seeing&amp;nbsp;SIPVicious Scanner Detection alerts a lot recently?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 00:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/281908#M76009</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-08-09T00:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/282147#M76037</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Join the club. I have seen them for over 7 years now. I created a special modified policy to drop the traffic. Yes it common and so are a bunch of others such as shodan, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 19:52:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/282147#M76037</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-09T19:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/292876#M77459</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;can you please let me know the policy details. I'll try to create it on my end. these are creating a lot of noise on my firewalls.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 13:37:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/292876#M77459</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-10-14T13:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/295114#M77766</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Same problem! Could you please share with me&amp;nbsp; the policy details?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 02:03:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/295114#M77766</guid>
      <dc:creator>Cliff_Lai</dc:creator>
      <dc:date>2019-10-30T02:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/295325#M77816</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp; Same problem! Could you please share with me&amp;nbsp; the policy details?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 00:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/295325#M77816</guid>
      <dc:creator>Cliff_Lai</dc:creator>
      <dc:date>2019-10-31T00:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/360605#M88122</link>
      <description>&lt;P&gt;Any chance I could get the details on the rule you created or is it posted somewhere?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 14:17:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/360605#M88122</guid>
      <dc:creator>Craig_Nackerud</dc:creator>
      <dc:date>2020-11-04T14:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/360777#M88134</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In your Vulnerability profile, set it to block anything medium and higher. SipVicious used to be low but since I block anything medium and higher, a custom policy is not longer required for me. But you can still block/unblock is with an exception.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1604529614363.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28505i96E95ADCE9CE5B0C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1604529614363.png" alt="OtakarKlier_0-1604529614363.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just change the action to like drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 22:40:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/360777#M88134</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-11-04T22:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/522113#M108173</link>
      <description>&lt;P&gt;I am a new user of a Palo Alto firewall. Where would I set up this policy? we are running version 9.1.12. Sorry, just a newbie here. I have tried finding it and am having problems.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bridget&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 18:40:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/522113#M108173</guid>
      <dc:creator>Bridget_Nee</dc:creator>
      <dc:date>2022-11-22T18:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/522131#M108178</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Welcome. Here is how you would perform this.&lt;/P&gt;
&lt;P&gt;Click on 'Objects' at the top&lt;/P&gt;
&lt;P&gt;Then 'Vulnerability Protection' on the left.&lt;/P&gt;
&lt;P&gt;Click on the name of the policy you wish to add the exclusion to (you cannot change the strict or default policies that are there by default, you will need to 'Clone' (at the bottom)&amp;nbsp; one and edit that.&lt;/P&gt;
&lt;P&gt;Once the profile is opened, click 'Exceptions tab.&lt;/P&gt;
&lt;P&gt;At the bottom click 'Show All Signatures', in the search/filter bar type SIPVicious&lt;/P&gt;
&lt;P&gt;This will display the policy that is alerting.&lt;/P&gt;
&lt;P&gt;Click the 'Enable' checkbox on the left.&lt;/P&gt;
&lt;P&gt;Click OK&lt;/P&gt;
&lt;P&gt;Click 'Commit' in the upper right to send the changes to the configuration (running and start)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 20:40:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/522131#M108178</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-11-22T20:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/522135#M108180</link>
      <description>&lt;P&gt;So first I have to set up a policy to check for these alerts?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 21:02:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/522135#M108180</guid>
      <dc:creator>Bridget_Nee</dc:creator>
      <dc:date>2022-11-22T21:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: SIPVicious Scanner Detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/522141#M108181</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;That is correct. The Security Policy is the one that actually does the enforcement on the configuration set on it. Say you have a security policy and no profiles set, then this policy will not be looking for such things as the SIPVicious scanner, etc. I would recommend setting up your Security Profiles first then add those to the Security Policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that makes sense.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 21:16:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-scanner-detection/m-p/522141#M108181</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-11-22T21:16:16Z</dc:date>
    </item>
  </channel>
</rss>

