cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L7 Applicator

Hi @hitachisas 

The default action for each Threat ID is determined by the Palo Alto Networks Threat Research team based on their internal evaluation criteria and several metrics. These criteria include the type of vulnerability, its impact, and its severity.

In some cases, you may see Threat IDs with High or Critical severity set to “Alert” as the default action. This is common for newly released threats, such as new CVEs or signatures. They are initially set to “Alert” for monitoring and observation. In later updates, the default action may be changed to “Reset” or "BLOCK" action if needed.

You can review Threat ID details, including severity and default actions, directly on the firewall (ensure the latest Threat content update is installed) or on ThreatVault

If required, you can manually override the default action and set a specific Threat ID to “Block” or “Reset.” This reference article will help you on it.

Hope it helps!

M

Check out my YouTube channel - https://www.youtube.com/@NetworkTalks

View solution in original post

Who rated this post