Except Specific IPs from port scan detection / Zone Protection

Reply
L4 Transporter

Except Specific IPs from port scan detection / Zone Protection

I have a highly regulated environment with multiple internal security zones. We need to be able to run our vulnerability scanning solution against servers in separate zones on a routine basis.

It was simple to exempt the scanner's IP from the Threat Prevention stuff (created a new security profile group which alerts on everything instead of blocking, and created a rule in the ACL to match against the scanner IP).

However, the vulnerability scanner is still prevented from completing its job because of zone protection (specifically, port scanning). I would hate to have to disable the zone protection rules or change them to alert EVERY time we wish to run a scan.

Any wonderful ideas?

Highlighted
L2 Linker

Re: Except Specific IPs from port scan detection / Zone Protection

There is a workaround to do this by creating and zone without any zone protection and use the IPs that you would like to be exempted as the loopback interface IP.

The steps required can be found here.

How to Exempt a Specific IP address from Zone Protection

https://live.paloaltonetworks.com/docs/DOC-3972

Hope this works for you.

Regards,

Narong

L4 Transporter

Re: Except Specific IPs from port scan detection / Zone Protection

Hi  Mackwage,

You can apply policy as u like and Mr. Narong is right you can use the same. its help full.....

Regards

Satish

L4 Transporter

Re: Except Specific IPs from port scan detection / Zone Protection

Thanks for you reply.

However it does not quite fit the scenario I am after. This seems like it would only work if you opened up one of your PUBLIC IPs. At that, it appears it would open up that public ip to port scanning from anywhere.

All devices in this scenario are internal. There is no NAT. The vulnerablity appliance is internal and has a static IP. We need to be able to scan devices in other "internal" zones.. and would like to open up port scanning from only the source vulnerability scanner.. and no other IPs.

L2 Linker

Re: Except Specific IPs from port scan detection / Zone Protection

In the example it shows that the external IP is the one that is being exempted. But instead of using the external IP subnet you can use the internal IP subnet as the loopback address.

L0 Member

Re: Except Specific IPs from port scan detection / Zone Protection

We experienced a similar challenge and needed to allow our QSVs vulnerability scanners to bypass IDS/IPS and scan unobstructed for vulnerabilities.  We achieved this by adding a Security Rule to allow the scanner IPs (no profiles) on TCP.

This eliminated the Scan Interference our QSV scanners were experiencing.  This same approach should work internal-to-internal also.

L4 Transporter

Re: Except Specific IPs from port scan detection / Zone Protection

This can still cause interference as port scans are blocked by the Zone Protection profile which is configured at the zone level and not via an ACL rule.

L0 Member

Re: Except Specific IPs from port scan detection / Zone Protection

This was a suggested way to resolve the issue from PA support and it did resolve our specific scan interference issues, but I agree it may not be the end all be all.

L3 Networker

Re: Except Specific IPs from port scan detection / Zone Protection

I don't see a way to create an exception for one IP-Address or Subnet. The zone protection applies to the whole traffic in this zone. You could deactivate the zone protection and try to add a DoS Protection Rule which is configured like the zone protection.

L0 Member

Re: Except Specific IPs from port scan detection / Zone Protection

Hello,

the link is no more accessable....Access to this place or content is restricted. If you think this is a mistake, please contact your administrator or the person who directed you here.

Can anyone provide the details or is there another solution ??

Regards

Michael

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!