Packet Based Attack Protection is enabled but it is not generating threat alerts.
10859
Created On 07/05/22 18:29 PM - Last Modified 01/28/25 20:14 PM
Symptom
- Packet Based Attack Protection is enabled in a Zone Protection profile.
- Testing the features IP Drop, TCP Drop, and ICMP Drop with packet-based attacks is not generating threat logs.
Environment
- Palo Alto Networks firewall.
- PAN-OS 8.1 and later versions.
- Zone protection.
Cause
- The log generation for Packet Based Attack Protection is disabled by default.
Resolution
- Use the operational CLI command:
> set system setting additional-threat-log on
- To ensure it has taken effect
FW> config t
FW#commit