Gmail imap traffic allowed but reset as threat

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Gmail imap traffic allowed but reset as threat

L1 Bithead

Hello everyone,

PA3220, it is already a couple of days as gmail imap traffic is allowed, but connection is reset as threat in Traffic Logs (see attached) Threat logs show nothing.

 

When checking traffic details, there is a strange app characteristics (see attached)

 

Any ideas?

1 accepted solution

Accepted Solutions

L3 Networker

Hello @igor.shpak 

Session end reason threat can be also from Data Filtering Security Profile and not only from Antivirus, Anti-Spyware or Vulnerability security profiles.

Please check also Data Filtering logs.

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

View solution in original post

7 REPLIES 7

L3 Networker

Hello @igor.shpak 

Session end reason threat can be also from Data Filtering Security Profile and not only from Antivirus, Anti-Spyware or Vulnerability security profiles.

Please check also Data Filtering logs.

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

L1 Bithead

Hello CosminM,

There is nothing in Data Filtering and URL filtering (sorry, pressed on Accept as Solution button by mistake)

L3 Networker

Hello @igor.shpak 

 

Please look into Detailed Log View by clicking on the Traffic Log's magnifying glass icon and check what was the reason to be classified as threat.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO 

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

This is what I did in the first place, pls see attached details.jpg from the first post

 

Basically it says

used-by-malware,able-to-transfer-file,has-known-vulnerability,tunnel-other-application,pervasive-use,is-saas,is-hipaa,is-soc2

 

L3 Networker

I am suggesting you check the entire Detailed Log View information and not only Details section from that view.

What is "Session End Reason: threat"? 

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

There is nothing else valuable in Detailed Log View

Issue solved, looks like a specific email in gmail mailbox was causing it. After deleting some newly arrived emails from Gmail web, issue was resolved

  • 1 accepted solution
  • 283 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!