<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>TOR Traffic</title><link>https://community.sophos.com/web-appliance/f/discussions/82926/tor-traffic</link><description>Hi, 
 We have deployed a block rule in firewall (Palo ALto) for a internal IP. I could see deny logs as well as allow logs for the same IP to different target addresses(In SIEM),could any one please reply,what could be the reason behind this. 
 
 Allow</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator></channel></rss>