06-03-2014 01:21 PM
Hi,
I have a PA3020 installed and operational in my enviroment.
I have a vulnerability profile (using "default" actions for detected threats) created and applied to a security policy that covers all zones.
I decided to do some testing and simulate an attack using metasploit.
Based on my results, I have a couple of questions:
Any help is greatly appreciated.
M
06-04-2014 01:45 AM
Hi
Re.1 - Please show us your security rule and configurations of profiles that are connected to this rule.
Re.2 - This is default PAN behavior, of course you should change this by creation your own profile in Object>Voulnerability Profile and changing from default to ie. block action
Try this tool too McAfee Evader - did You use it?
Regards
Slawek
06-04-2014 10:04 AM
Thanks for the reply.
What's the best method to show the policy and profile configuration?
M
06-04-2014 10:22 AM
Honestly screenshots would work... I can personally attest that I have seen PAs that I've tested pick up on Metasploit sessions, just as an aside
06-04-2014 10:38 AM
Here are screenshots of the Security Policy (WSASECURITYPOLICY0):
And the Vulnerability Profile (MJVULNERABILITY00):
Let me know if you need more.
M
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!