Creating Data Filtering Profile in PA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Creating Data Filtering Profile in PA

L1 Bithead

Hi,

I am creating a data filtering profile and I want to only allow alert threshold, not to block, so I need to know how much value to add inside.

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hello @PPradhan

 

could you refer to this KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldCCAS

 

In nutshell, set the Block Threshold to 0 and Alert Threshold to non zero value. Alert Threshold tells firewall if it sees a data pattern X number of times within the same session to generate an alert. I would start with value 2 or 3 and tune it up if necessary.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

View solution in original post

Cyber Elite
Cyber Elite

Thank you for reply @PPradhan

 

this is correct. Alert means traffic is allowed, only log is generated. Here is a reference to the documentation: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles#id6272be37-1ce2-...

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello @PPradhan

 

could you refer to this KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldCCAS

 

In nutshell, set the Block Threshold to 0 and Alert Threshold to non zero value. Alert Threshold tells firewall if it sees a data pattern X number of times within the same session to generate an alert. I would start with value 2 or 3 and tune it up if necessary.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi PavelK,

I have created data patterns profile and data filtering profile and keep threshold alerts to 20block to 0 and severity to low and added inside the security rule.

>> In monitor > Data Filtering tab I can see the logs are coming and its showing alerts so in that case the traffic is not blocked?

Cyber Elite
Cyber Elite

Thank you for reply @PPradhan

 

this is correct. Alert means traffic is allowed, only log is generated. Here is a reference to the documentation: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles#id6272be37-1ce2-...

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 2 accepted solutions
  • 1732 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!