- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-26-2016 08:12 AM
PA-3020
Recently I've had several users get a "Virus/Spyware Download Blocked" page on random sites. Normally they get it on google searches. If they refresh, sometimes the error stays, and sometimes it just takes them to the page.
It even happened to me the first time I tried coming to this site, but a refresh took me here. Here's an example of the error for another site I tried to go to.
When I log into the PA, and look under Monitor->Threat, I have the following errors:
I'm fairly new to PA systems, and it seemed odd to me, that my IP address was listed as the Attacker, and google was listed as the Victim. Also, for my traffic at least, they are listed as Suspicious TLS Evasion Found, on what looks to be google ads. I listed the URL's at the top right of the above image. Any ideas on what could be causing this.
In addition, we've also seen things like broken images from sites, that show as the same error in the PA "Suspicious TLS Evasion Found", or Suspicious HTTP Evasion Found.