| Where Can I Use This? | What Do I Need? |
- PAN-OS 12.2 and later
- Strata Cloud Manager
- PAN-OS 11.1.x and later (EDL-based)
|
- Advanced IP Defense license
- Admin access to firewall or Strata Cloud Manager
|
Advanced IP Defense maintains a false positive rate of 1% or less for IP attribution. However, in some cases, a legitimate IP address may be incorrectly assigned an attribute that causes your policy rules to block or alert on traffic that should be allowed. When this occurs, you can mitigate the immediate impact by creating an exception or allowlist entry, and then report the false positive to Palo Alto Networks so the research team can investigate and correct the attribution.
False positives in IP attribution can occur for several reasons. Shared hosting environments may cause an IP to inherit attributes from a malicious tenant that previously used the same address. Cloud provider IP ranges are frequently reassigned between customers, and attribution updates may lag behind the reassignment. Legitimate services that exhibit behavior similar to malicious activity, such as high-volume scanning for security research, may be misclassified. Reporting false positives helps the Advanced IP Defense research team refine their detection methods and update the IP attribute database for all customers.