Abnormal SSL traffic on 443

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Abnormal SSL traffic on 443

L1 Bithead

Hello I was looking into an pan threat on the logs I noticed that I Abnormal traffic is being detected  does anyone have any ideas to minimize the threat or Best Practices or more possible features I can add to the Panorama

 

Thanks  

1 REPLY 1

L5 Sessionator

From your description, I understand that you are seeing "Abnormal SSL traffic on port 443 (54699)" detected on the firewall and on the panorama you are seeing the threat log forwarded by the firewall.
https://threatvault.paloaltonetworks.com/?query=Abnormal SSL traffic on 443&type=

 

I would advise you to take a threat pcap and verify if the traffic is actually abnormal. Most likely, the SSL handshake is missing.
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/take-packet-captures/take-a-th...

 

If it's a true positive, you can change the default action to block the traffic to minimize the threat since it's an abnormal traffic.
STEPS TO CHANGE THE DEFAULT ACTION FOR SIGNATURES
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm3KCAS

 

  • 3525 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!