SDP-685 | rrun() misinterpreted by Palo Alto firewall as attack. The rrun()... function for running code on a remote machine creates a temporary script, and then uses scp to copy the script to the remote machine where the script is then executed. Normally, this works fine, but it is possible that a Palo Alto filewall will block this with a "Threat" indication saying "SSH User Authentication Brute Force Attempt". When this occurs, the result is an error message containing text like the following: lost connection rrun(): Failed to copy temp command script to host bos-helix-02. If the command the script is attempting to run is executed manually on the command line, it works. It is blocked by Palo Alto Networks (PAN) firewall when called via the script. « | |
Add Job |