Threat ID in the ranges between 8700-8799, Packet Based Attacks Protections in "Zone Protection" profiles

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Threat ID in the ranges between 8700-8799, Packet Based Attacks Protections in "Zone Protection" profiles

L2 Linker
My customer is worry for log about threat id 8725.
this log is no impact on this device?
 
Screen Shot 2565-09-05 at 18.23.08.png
 
 
 
 
 
 
 
 
I know this is the expected behavior. Exceptions for these signatures are not to be found under the "Vulnerability Protection Profile".
2 REPLIES 2

L2 Linker

Anyone can give answer or not?
I need to know this log is no impact on this device?

L5 Sessionator

Here's what it means.
Threat-ID 8725: This event detects and strips the TCP Fast Open option (and data payload, if any) from the TCP SYN or SYN-ACK packet during a TCP three-way handshake.

 

It may disrupt applications that use TCP Fast Open.
There's no security impact on the device.

 

As already mentioned above, there's no exception option for 8725 in the vulnerability profile.
Reference: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkrWCAQ

  • 2388 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!