Antivirus/Anti-Spyware Response Page not working

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Antivirus/Anti-Spyware Response Page not working

L2 Linker

Hey Community!

 

I noticed that our Firewall (PA-3020, PAN-OS 7.1.6) does not serve an Antivirus/Anti-Spyware block page.

When I use http://www.eicar.org/85-0-Download.html to test it, I can see that it is blocked.

ThreatLog shows action "reset-both" but in the Browser (tested with Firefox 50.1.0 and IE 11 11.576.14393.0/Win10) I don´t get the desired and configured Block-Page.

 

URL-Filter and Application block pages are working as expected, but AV/Spyware block page is not working.

 

SSL-Decryption is enabled and if I use https://secure.eicar.org/eicar.com for download, the download is also blocked, but I don´t get a block page. So no matter if http or https is used, the file is blocked but no response page is served.

 

We also have a PA-500 - PAN-OS 7.1.6, no  SSL-Decryption active - response pages are configured and I get the same result as on our PA-3020, that is: URL-Filter and Application block pages are working as expected, but AV/Spyware block page is not served to the client browser, although the download is blocked.

 

Does anyone else have the similar issues?

 

Thanks,

Alex.

 

 

3 REPLIES 3

L5 Sessionator


Thanks VinceM,
but as far as I know, you can't enable nor disable AV-Response page. At least there is no option for doing that.
Application response page is enabled and as I mentioned in my original post, App and Url response pages or working correctly.

The following command is set - required for SSL decrypt.
set deviceconfig setting url dynamic-url yes

the managment profile for the egress interface is set to enable response pages.
I know for sure, that the AV response page worked when we first implemented the firewall 3 years ago and I think that was on
PAN-OS 5.X
I don't know when it stopped working 😞

Alex.

Hello,

 

I have the same behavior, response pages for unencryped flows are working, response pages for encrypted (with SSL interception) app + URL filtering are also working fine.

 

However other encrypted flows (with SSL interception) like AV, vulnerability are not working but I think it's by designed for the transparent proxy: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0

 

Does someone know a way to change the behavior even if it's not a proper response page but something that may challenge the user that the firewall is blocking something?

 

Thanks

  • 7079 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!