Need confirmation from Palo alto on DNS Trojan ShadowPad Detected

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Need confirmation from Palo alto on DNS Trojan ShadowPad Detected

L2 Linker

1. Customer has encountered the new threat alert named DNS Trojan ShadowPad Detected in their network but the traffic is passing through Palo alto firewall and it is allowed and no threat alerts are triggered in Palo Alto Firewall.

 

2. TLS Version 1.1 Protocol Deprecated - Need to Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.

3.IP Forwarding Enabled - Need to disable IP forwarding.

 

Please suggest on this.

2 REPLIES 2

Hi @Purushotham ,

If you have support account you can access https://threatvault.paloaltonetworks.com/ where you can search available PAN signatures/protections. If you search for "ShadowPad" - https://threatvault.paloaltonetworks.com/?query=ShadowPad&type= only AV signatures are available.

 

Can you provide more details on the alert your customer have received?

- What device has triggered this alert?

- What this alert is detecting? What traffic has triggered this alert?

 

2. TLS Version 1.1 Protocol Deprecated - Need to Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.

It is not very clear what you are trying to do, but I would assume you want to restrict TLS 1.1 traffic over PAN firewall. If that is a case you need to define SSL decryption profile - https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-concepts/ssl-protoco... As you can see you can only do this only for decrypted traffic.

1. Create SSL decryption profile

2. Configure SSL protocol settings to match your requirements - min=TLS 1.2 and max=max (this will tell the FW to use the latest which it could support at the moment is 1.3, if in the future OS is updated to support higher it will automatically apply that)

3. Create SSL decryption rule matching the traffic for which you want to enforce TLS1.2/1.3 and set action to decrypt, selecting the profile you created earlier

 

 

3.IP Forwarding Enabled - Need to disable IP forwarding.

This questions is not clear at all. It looks like finding from vulnerability scan or PenTest from endpoint. In order to assist you we will need little bit more clarification and background info.

L2 Linker

Hi Alex,

Thank You for the response. I have opened a case with TAC and it is being addressed accordingly.

 

 

  • 1039 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!