Manage PAN-OS Shield Threat Exceptions
Focus
Focus
Next-Generation Firewall

Manage PAN-OS Shield Threat Exceptions

Table of Contents

Manage PAN-OS Shield Threat Exceptions

Add threat exceptions to the PAN-OS Shield vulnerability protection profile to override the action for specific threat IDs.
Where Can I Use This?What Do I Need?
  • NGFW
  • PAN-OS 12.2.2 and later
The PAN-OS Shield vulnerability protection profile is read-only—you cannot modify the signatures or their default actions directly. However, if a signature triggers a false positive that impacts your environment, you can add a threat exception to override the action for that specific threat ID. Threat exceptions are stored separately from the content-delivered profile and persist across content updates.
  1. Select ObjectsPAN-OS ShieldVulnerability Protection.
  2. Click the PAN-OS Shield vulnerability protection profile.
  3. Select the Exceptions tab.
    The tab displays a table of threat signatures with the following columns: ID, Threat Name, IP Address Exemptions, CVE, Category, Severity, Action, and Packet Capture.
    Clicking ID, CVE, Category, or Severity for an entry adds it as a search parameter. Clicking the Threat Name opens a Threat Details window showing the name, ID, description, severity level, and associated CVE.
  4. Locate the threat ID that you want to override.
    You can find the threat ID in the threat logs generated when PAN-OS Shield detects a match.
  5. For the target entry, click Action and choose the action to apply for this threat ID.
    • alert—Generate a threat log but allow the traffic.
    • allow—Allow the traffic without taking action.
    • Block IP—Block traffic from the source IP for a specified duration.
    • Default (Allow)—Use the default action defined by the content-delivered profile, which allows the traffic.
    • Drop—Silently drop the traffic.
    • Reset Both—Send a TCP reset to both client and server.
    • Reset Client—Send a TCP reset to the client.
    • Reset Server—Send a TCP reset to the server.
  6. (Optional) For the target entry, click Packet Capture and choose single-packet or extended-capture to capture traffic when this threat ID triggers.
  7. (Optional) Click IP Address Exemptions to add exemptions that exclude specific source addresses from this threat exception.
  8. Click OK.
  9. Commit your changes and reboot the firewall.