Exception for DNS signature which is showing the ID as 0 and FQDN as unknow

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Exception for DNS signature which is showing the ID as 0 and FQDN as unknow

L2 Linker

Getting false positive for the Link tivoli.com.qa as threat name(68360795).Its getting DNS sinkholing.Can anyone help to know how we  give the exception only for the threat ID 68360795 and the Fqdn is tivoli.com.qa. Attached screenshots below

 

DNS-Sinkholing-tivoli.pngAntispyware Policy-tivoli.png

7 REPLIES 7

Hi @hisingh ,

 

Thanks for your reply.Please find the detailed threat log for ID 68360795Detailed THreat Logsss.png

as  mentioned before most 68360795 is unknow in my firewall also most of the signatures are unknown. I checked in another firewall which is having same content versionContent Version.JPG and i can see the 68360795 is

DNS-Sinkholing-From another firewall.jpg

visible.But same in my firewall showing as unknown.If you can check the previous screenshots related to exception you can see the ID eg: 327772845 which is also showing as unknown.For confirming please check this ID in your FW

Did you check the threat vault connectivity from PA devices.

Test connectivity to the Threat Vault using:
> test threat-vault connection 

 

or you can check it from System logs.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PM0BCAW

 

NpN

Hi Nijith,

 

Thanks for your commments. Now its working after changing the DNS to public.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!