Panorama and Scan Type threats

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Panorama and Scan Type threats

L4 Transporter

Anyone know if Panorama is supposed to show Scan type threats in the Threats or Unified views under Monitoring?  I'm investigating why some of our Autodesk software on campus is having problems reaching the licensing server... Panorama didn't show any problems and I can see allowed traffic but then noticed drops in a packet capture.  Checking the Threats on the individual firewalls showed a number of "SCAN: TCP Port Scan" with the action "block-ip".

 

I'm also not sure how I'm getting block-IP here.  That may it's default action but the Vulnerability Protection profile I have applied to that security policy should just alert on Medium or lower and the scan threat it is identifying is classified as Medium.

 

Thanks

4 REPLIES 4

Cyber Elite
Cyber Elite

that's a zone protection action rather than a threat prevention signature

zone protetion.png

 

they get added to the system log, so you probably don't have log forwarding enabled for system logs

panorama forwarding.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi @reaper

 

Ok I see that now in Zone protection, however I have System logs already set to forward to Panorama.  We've actually got them split out for some reason... instead of "All Logs" we have one fore each severity level but every one of them has Panorama checked.

 

Is it possibly due to a version difference?  We're running Panorama 8.0.1 and 7.1.8 on the firewalls.

those versions should not be an issue

is there a difference between all the profiles? if they're all identical (ecept for the severity filter) it might be better to combine them all into one profile. 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

I believe the only difference is the severity filter.  I don't recall setting it up that way but I don't see why I shouldn't be able to just change it to All Logs.

 

We may have just solved the overall problem by telling the client Autodesk software's config to use a specific port which seems to prevent the application from initiating a port scan.

 

I definitely want to get those logs showing up on Panorama though... having an incomplete picture without going to the firewalls kind of defeats the purpose.

  • 2344 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!