- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-02-2017 08:21 AM
Anyone know if Panorama is supposed to show Scan type threats in the Threats or Unified views under Monitoring? I'm investigating why some of our Autodesk software on campus is having problems reaching the licensing server... Panorama didn't show any problems and I can see allowed traffic but then noticed drops in a packet capture. Checking the Threats on the individual firewalls showed a number of "SCAN: TCP Port Scan" with the action "block-ip".
I'm also not sure how I'm getting block-IP here. That may it's default action but the Vulnerability Protection profile I have applied to that security policy should just alert on Medium or lower and the scan threat it is identifying is classified as Medium.
Thanks
05-02-2017 08:51 AM
that's a zone protection action rather than a threat prevention signature
they get added to the system log, so you probably don't have log forwarding enabled for system logs
05-02-2017 08:58 AM
Hi @reaper
Ok I see that now in Zone protection, however I have System logs already set to forward to Panorama. We've actually got them split out for some reason... instead of "All Logs" we have one fore each severity level but every one of them has Panorama checked.
Is it possibly due to a version difference? We're running Panorama 8.0.1 and 7.1.8 on the firewalls.
05-02-2017 09:16 AM
those versions should not be an issue
is there a difference between all the profiles? if they're all identical (ecept for the severity filter) it might be better to combine them all into one profile.
05-02-2017 10:17 AM
I believe the only difference is the severity filter. I don't recall setting it up that way but I don't see why I shouldn't be able to just change it to All Logs.
We may have just solved the overall problem by telling the client Autodesk software's config to use a specific port which seems to prevent the application from initiating a port scan.
I definitely want to get those logs showing up on Panorama though... having an incomplete picture without going to the firewalls kind of defeats the purpose.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!