Objects > PAN-OS Shield > Vulnerability Protection
Focus
Focus
Next-Generation Firewall

Objects > PAN-OS Shield > Vulnerability Protection

Table of Contents

Objects > PAN-OS Shield > Vulnerability Protection

View PAN-OS Shield vulnerability protection signatures and manage threat exceptions to override actions for specific threat IDs.
ObjectsPAN-OS ShieldVulnerability Protection
PAN-OS Shield uses a vulnerability protection profile that is delivered and updated through content updates. This profile is read-only—you cannot modify the signatures or their default actions directly. However, you can add threat exceptions to override the action for specific threat IDs when you need to address false positives in your environment.
You must enable PAN-OS Shield globally under DeviceSetupPAN-OS Security before the vulnerability protection profile is available.
The PAN-OS Shield vulnerability protection profile contains signatures that detect exploitation attempts targeting PAN-OS services in control traffic. When PAN-OS Shield is enabled, the firewall applies this profile to inspect inbound GlobalProtect control traffic before it reaches the management plane.
The following table describes the settings on the Exceptions tab:
Field
Description
ID
The unique threat ID for the signature. Clicking the ID adds it as a search parameter to filter the table.
Threat Name
The name of the threat signature. Click the threat name to open a Threat Details window that displays the name, ID, description, severity level, and associated CVE for the signature.
IP Address Exemptions
Click to add IP address exemptions that exclude specific source addresses from the threat exception. Traffic from exempted IP addresses is not subject to the overridden action for this threat ID.
CVE
The Common Vulnerabilities and Exposures identifier associated with the threat signature. Clicking the CVE adds it as a search parameter to filter the table.
Category
The threat category classification for the signature. Clicking the category adds it as a search parameter to filter the table.
Severity
The severity level assigned to the threat signature. Clicking the severity adds it as a search parameter to filter the table.
Action
Click to override the action taken when this signature triggers. Choose from the following options:
  • alert—Generate a threat log but allow the traffic.
  • allow—Allow the traffic without taking action.
  • Block IP—Block traffic from the source IP for a specified duration.
  • Default (Allow)—Use the default action defined by the content-delivered profile, which allows the traffic.
  • Drop—Silently drop the traffic.
  • Reset Both—Send a TCP reset to both client and server.
  • Reset Client—Send a TCP reset to the client.
  • Reset Server—Send a TCP reset to the server.
Packet Capture
Click to configure packet capture when this signature triggers. Choose from the following options:
  • disable—Do not capture packets.
  • single-packet—Capture a single packet when the threat is detected.
  • extended-capture—Capture multiple packets to provide additional context for threat analysis.