Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
Why a vulnerability signature action is set as "alert" while its severity is critical or high

Why a vulnerability signature action is set as "alert" while its severity is critical or high

34012
Created On 03/31/20 19:29 PM - Last Modified 08/16/24 01:07 AM


Question


A vulnerability signature action is set as "alert" while the severity of the signature is critical or high. The action should be the one that can block the traffic, such as "reset-client", "reset-server", "reset-both", "drop", "block-ip".


 


Environment


PAN-OS 
Threat Prevention license


Answer


There are two circumstances when a vulnerability signature action is "alert" and the severity is critical or high.
  • Recently found vulnerability:
    • The default action is set as "alert" when we release a new vulnerability signature, despite the severity. Palo Alto Networks observes the behavior of the signature for some time (a few weeks) before changing the action to be the one that can block the traffic, such as "reset-client", "reset-server", "reset-both", "drop", "block-ip".
  • A vulnerability that has existed for a while:
    • Another factor is Palo Alto Networks' internal algorithm. For some signatures, the action is "alert" even if the severity is critical/high and the vulnerability is not a recent one. It is due to Palo Alto Networks' internal logic depending on metrics, type of vulnerability, direct vs indirect effect,  soak sites, and feedback from production sites.


What if I want to block based on severity despite of the default action: 
  • The action of the signature can be changed from the default action to a different one. The example below shows that the simple-server-critical rule overrides the default action for any vulnerability signature that has a severity of critical; host type is server.
image.png
  • The simple-client-critical rule overrides the default action for any vulnerability signature that has severity critical and the connection is initiated by the client.
image.png

 

See Also:



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPNSCA4&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language