Antivirus Profile and Default Actions

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Antivirus Profile and Default Actions

L2 Linker

I've been looking at our PA, and I've found that it's detecting viruses being delivered in SMTP traffic. The PA is alerting, but taking no further action.

 

Looking at this guide here, I understand that Palo Alto have this set based on the best recommendation at the time.

https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/policy/best-practice-internet-gateway-secu...

 

I'm wondering why we wouldn't want to block viruses on the PA, like we do with http(s) traffic by default?

Is this because we're assuming that there will be some other AV on the mail server?

Or is it because we're not assuming that the PA will not go on the edge of the network?

 

Thanks!

1 accepted solution

Accepted Solutions

Community Team Member

Hi @Luke_R ,

 

Best practice would be to use the reset-both action to return a 541 response to the sending SMTP server to prevent it from resending the blocked message. 

 

https://docs.paloaltonetworks.com/best-practices/9-1/internet-gateway-best-practices/best-practice-i...

 

Cheers !

-Kiwi.

 

 

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

2 REPLIES 2

Community Team Member

Hi @Luke_R ,

 

Best practice would be to use the reset-both action to return a 541 response to the sending SMTP server to prevent it from resending the blocked message. 

 

https://docs.paloaltonetworks.com/best-practices/9-1/internet-gateway-best-practices/best-practice-i...

 

Cheers !

-Kiwi.

 

 

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Thanks, this makes sense to me. I'm surprised they don't do this out of the box though.

  • 1 accepted solution
  • 2469 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!