- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-14-2017 06:33 AM
I looked in the threat database and PA classifies this URL Inbox update.newinfoclientstack.com as maleware. Is there a way to know if this is covered by the threat prevention subscription? There were no details in how to deal with it in the database
07-14-2017 07:13 AM
The newinfoclientstack.com domain is only listed as malware because of the listing in PAN-DB URL Classifications and therefore isn't covered with the threat prevention subscription. The only thing that the threat prevention license is going to cover is antivirus, anti-spyware, and vulnerability proctection updates.
Keep in mind that you still have access to URL filtering by the devices Base db; in this case it doesn't do you much good as the Base db is listing it as a content-delivery-network while the Cloud db is listing it as Malware.
07-14-2017 07:19 AM
This is the URL that was requested to be blocked, but i see no evidence it has ever tried on the firewall. Just trying to figure out the best way to deal with these issues and not make excessive work
07-14-2017 07:24 AM
Do you have an active 'blacklist' so to speak? You could build an EBL that was only for addresses that were going to be blocked and then put any such request like this in that 'blacklist' policy. If you utilize MineMeld you could even build in an age-out limit so that entries are automatically removed after x amount of time. That's how I deal with requests such as this.
07-14-2017 07:44 AM
We were able to add it to our exisiting MISP list so we are good to go, But it is good to know that I could create a a seperate rule and profile
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!