- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-21-2022 07:26 AM
Hello I was looking into an pan threat on the logs I noticed that I Abnormal traffic is being detected does anyone have any ideas to minimize the threat or Best Practices or more possible features I can add to the Panorama
Thanks
01-31-2022 08:41 PM
From your description, I understand that you are seeing "Abnormal SSL traffic on port 443 (54699)" detected on the firewall and on the panorama you are seeing the threat log forwarded by the firewall.
https://threatvault.paloaltonetworks.com/?query=Abnormal SSL traffic on 443&type=
I would advise you to take a threat pcap and verify if the traffic is actually abnormal. Most likely, the SSL handshake is missing.
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/take-packet-captures/take-a-th...
If it's a true positive, you can change the default action to block the traffic to minimize the threat since it's an abnormal traffic.
STEPS TO CHANGE THE DEFAULT ACTION FOR SIGNATURES
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm3KCAS
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!