<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DShield top 20 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12821#M9398</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you are currently using the DShield top 20 list on your outbound traffic and have found any benefits from it? Was it easy to configure? Why did you configure it as an outbound rule not and inbound rule? Do you have it as your top rule and have everything passing through it first?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Apr 2015 15:30:58 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2015-04-02T15:30:58Z</dc:date>
    <item>
      <title>DShield top 20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12818#M9395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is anyone currently using this dshield top 20 list subscription? How well does it work/ Is anyone blocking inbound, outbound or both? What is the best way to configure it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Apr 2015 14:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12818#M9395</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-04-01T14:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: DShield top 20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12819#M9396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So has anyone used any dynamic block lists? If so how well did they work and what did they work on?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 13:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12819#M9396</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-04-02T13:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: DShield top 20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12820#M9397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like you, I was curious about using this and have configured a specific outbound rule which is currently allowing the traffic. Monitoring on that specific rule is currently showing outbound DNS, web-browsing and 360-safeguard-update traffic destined for the DShield top 20.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 15:27:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12820#M9397</guid>
      <dc:creator>John_S</dc:creator>
      <dc:date>2015-04-02T15:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: DShield top 20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12821#M9398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you are currently using the DShield top 20 list on your outbound traffic and have found any benefits from it? Was it easy to configure? Why did you configure it as an outbound rule not and inbound rule? Do you have it as your top rule and have everything passing through it first?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 15:30:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12821#M9398</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-04-02T15:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: DShield top 20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12822#M9399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It was easy to configure. I followed this document "&lt;A href="https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/" style="font-size: 13.3333330154419px;" title="https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/"&gt;Subscribing to the DShield Top 20 on a Palo Alto Networks Firewall - SANS Internet Storm Center&lt;/A&gt;" but used a https instead of http for obtaining list updates &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This initial configuration is a cautious first step in implementing the blocklist. I've only done an initial outbound rule as I wanted to see how much traffic would be matched and what exact types would show up. Like the botnet reporting it is currently giving me some visibility into internal hosts that need to be looked at closer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've placed the rule near the top of the inside-&amp;gt;outside rules after some of the other existing block rules but before the permit rules start. Based on how this initial testing turns out, I'll look at implementing inbound rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 15:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12822#M9399</guid>
      <dc:creator>John_S</dc:creator>
      <dc:date>2015-04-02T15:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: DShield top 20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12823#M9400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so you have downloaded the subscription for dshield which is a list of know bad ips to block any thing from the trust side to the untrusted side. You aren't allowing any of the internal traffic to query, contact or connect to anything on that list. Is this list dynamic? When do you plan to add a inbound list?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 18:51:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12823#M9400</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-04-02T18:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: DShield top 20</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12824#M9401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you ever used or heard of this list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" title="https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt"&gt;https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Apr 2015 15:23:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dshield-top-20/m-p/12824#M9401</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-04-13T15:23:46Z</dc:date>
    </item>
  </channel>
</rss>

