Tips & Tricks: WildFire File-type Based Cloud Selection

Tips & Tricks: WildFire File-type Based Cloud Selection

10372
Created On 09/25/18 19:02 PM - Last Modified 06/01/23 09:33 AM


Resolution


Some security regulations may require that sensitive information not leave the Data Center, even through encrypted means, which excludes these files from being scanned for infections by the WildFire Cloud. 

 

The WF-500 appliance alows an organization to leverage the strength of WildFire sandbox analysis in a private cloud environment.

 

Sending all internal files to the private cloud, however, may waste resources if not all files are bound by strict regulations. An example would be PDF files that may potentially contain secret or sensitive information and PE files from the internet (PuTTY, pdf reader, other useful tools and so on) that may have been already scanned by the public WildFire cloud.

 

Starting from PAN-OS 7.0, the security profile for WildFire was split off from the File Blocking profile to give an administrator more control over which actions to take for each File Type that is of interest. This includes choosing which cloud, private or public, to send specific file types to within the same security profile.

 

2016-09-06_12-35-50.jpg

 

This also allows an admin to have file types that are not supported by the WF-500 appliance, like APK files, to be forwarded to the public cloud.

 

The direction of the file, upload or download, can also be taken into consideration when selecting public or private cloud:

2016-09-06_13-45-40.jpg

 

 

The IP or hostname of the public and private cloud can be configured individually via Device > Setup > WildFire.

2016-09-06_13-41-08.jpg

 

And individual service routes can be created via Device > Setup > Services > Service Route Configuration > Customize, so cloud upload paths can be segregated.

2016-09-06_13-53-09.jpg

 

I hope you found this Tips & Tricks useful. Feel free to leave comments below!

 

Reaper



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTACA0&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language