- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-23-2023 01:04 AM
1. Customer has encountered the new threat alert named DNS Trojan ShadowPad Detected in their network but the traffic is passing through Palo alto firewall and it is allowed and no threat alerts are triggered in Palo Alto Firewall.
2. TLS Version 1.1 Protocol Deprecated - Need to Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
3.IP Forwarding Enabled - Need to disable IP forwarding.
Please suggest on this.
07-05-2023 06:12 AM
Hi @Purushotham ,
If you have support account you can access https://threatvault.paloaltonetworks.com/ where you can search available PAN signatures/protections. If you search for "ShadowPad" - https://threatvault.paloaltonetworks.com/?query=ShadowPad&type= only AV signatures are available.
Can you provide more details on the alert your customer have received?
- What device has triggered this alert?
- What this alert is detecting? What traffic has triggered this alert?
2. TLS Version 1.1 Protocol Deprecated - Need to Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.
It is not very clear what you are trying to do, but I would assume you want to restrict TLS 1.1 traffic over PAN firewall. If that is a case you need to define SSL decryption profile - https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-concepts/ssl-protoco... As you can see you can only do this only for decrypted traffic.
1. Create SSL decryption profile
2. Configure SSL protocol settings to match your requirements - min=TLS 1.2 and max=max (this will tell the FW to use the latest which it could support at the moment is 1.3, if in the future OS is updated to support higher it will automatically apply that)
3. Create SSL decryption rule matching the traffic for which you want to enforce TLS1.2/1.3 and set action to decrypt, selecting the profile you created earlier
3.IP Forwarding Enabled - Need to disable IP forwarding.
This questions is not clear at all. It looks like finding from vulnerability scan or PenTest from endpoint. In order to assist you we will need little bit more clarification and background info.
07-10-2023 12:10 AM
Hi Alex,
Thank You for the response. I have opened a case with TAC and it is being addressed accordingly.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!