Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
About Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.

Discussions

Welcome to the Threat & Vulnerability Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4170 Views
  • 0 replies
  • 0 Likes

Dynamic IP lists and FQDN?

The only type of external dynamic list i appear to be able to specify in my firewall policy is a dynamic IP list (not a dynamic domain list). And the formatting of such lists appears to be purely for IP addresses. So my question is, how can i specify fully qualified domain names in a dynamic list usable in a firewall policy?

Resolved! Query -> Data Center Best Practice Antivirus Profile

Hi Community. The below article states that "The Antivirus profile has decoders that detect and prevent viruses and malware from being transferred over six protocols: HTTP, SMTP, IMAP, POP3, FTP, and SMB": https://www.paloaltonetworks.com/documentation/81/best-practices/best-practices-data-center/data-center-best-practice-security-policy/how-to-...

ash83 by L2 Linker
  • 10298 Views
  • 7 replies
  • 0 Likes

URL Filtering Team creating MORE of a risk

Hi all, Does anyone know how to directly interact with the URL filtering team besides urlfiltering.paloaltonetworks.com? I would especially like to reach a manager. I am having huge problems with them. I keep submitting sites on which scanners have found malware (usually after one of my users visits them) and they keep refusing to recategoriz...

SSL DERYPTION : How to automate URL/domaine decryption Exclusion properly?

Use case : Ours users go through Palo alto for internet access. Decryption feaures has been enabled.When users try to access to internet may failed because the decryption-error.We need a solution to automate URL SSL decryption exclusion and log urls excluded for review. Perfectly in a dynamics external list or in a custom url category. Theses dy...

ingdrame by L0 Member
  • 6035 Views
  • 2 replies
  • 1 Likes

How Palo Alto Networks Identifies GnuTLS Server Hello Session ID Heap Buffer Over Without Decryption

HI All, We detected Vulnerability: 36926 ID- GnuTLS Server Hello Session ID Heap Buffer Overflow in Palo Alto firewall. In our cutomers Firewall enviroment we not enable the SSL Descryption Feature. Customers Queries us.. How and Why Palo Alto able detect the Vulnerability threat without the SSL? Can Any one assist us on this?

Nono by L1 Bithead
  • 5381 Views
  • 1 replies
  • 0 Likes

PAN-DB Connectivity

Hi, We are faced with the connectivity issue when we tried to download the URL filtering DB from PAN-DB. As the firewall has an external interface to the internet, we have changed the service route for “Palo Alto Networks Services” to the external interface. However, we are not able to get connected to the PAN-DB. We are able to ping to the PAN-...

Need to Verify traffic.

Hello All, I am using PA-820, i only have cli access to device. I will require to verify traffic from a particular source and destination on the device. Do we have any commands to do that ? May be something like packet tracer to get all the routes / ACL / NAT supporting. Thanks in advance.

Increased FP's for Wildfire Viruses

Has anyone noticed an increase in the number of false-positives being generated by Wildfire in the last few weeks? I seem to be getting a increased number of alerts for WF learnt viruses on apps that have never caused issues before. Always worried that it is indeed a real alert, but as far as we can tell it's not. Just wondering if anyone else ...

apackard by L4 Transporter
  • 5113 Views
  • 2 replies
  • 0 Likes

Resolved! UltraSurf 18.02

Hi, I´m getting some trouble trying to block ultrasurf. First i blocked it with App-ID and everything was ok, until some users of the internal network downloaded a new version to avoid URL-filtering. Summary of logApplication:SSLCategory:UnknownNAT Port: 443IP protocol: tcp I can´t block SSL or Unknown category because we have an active GlobalPr...

  • 545 Posts
  • 78 Subscriptions