<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Advanced Wildfire Allowing High Severity Verdicts but blocking Informational in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/advanced-wildfire-allowing-high-severity-verdicts-but-blocking/m-p/575915#M2576</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163815"&gt;@laurence64&lt;/a&gt;&amp;nbsp;- are you in a position to share your profile and policy configurations?&lt;/P&gt;</description>
    <pubDate>Sun, 04 Feb 2024 22:36:46 GMT</pubDate>
    <dc:creator>iarobertson</dc:creator>
    <dc:date>2024-02-04T22:36:46Z</dc:date>
    <item>
      <title>Advanced Wildfire Allowing High Severity Verdicts but blocking Informational</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/advanced-wildfire-allowing-high-severity-verdicts-but-blocking/m-p/572692#M2415</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have Advanced Wildfire in our Lab env and have noticed something very odd, when the firewall is submitting any files to Wildfire if they are returning "informational" they are blocked, if they are returning Malicious and "High" the action is allow, this has also been confirmed by the fact that the samples of Malware are being blocked by the Windows defender running on the test desktop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured decryption and allowed the forwarding of decrypted traffic ( I assume that the submissions would not show if this was not working correctly ) and have confirmed that the traffic is running across the defined rule and that rule has the Wildfire and Anti-virus profiles that are set to reset everything, this is very strange behavior and I am hoping that it is an omission in my configuration somewhere.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally this does not seem to matter if the session is http or http2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be greatly received as this has me scratching my head at the moment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance,&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 10:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/advanced-wildfire-allowing-high-severity-verdicts-but-blocking/m-p/572692#M2415</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2024-01-11T10:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Wildfire Allowing High Severity Verdicts but blocking Informational</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/advanced-wildfire-allowing-high-severity-verdicts-but-blocking/m-p/575915#M2576</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163815"&gt;@laurence64&lt;/a&gt;&amp;nbsp;- are you in a position to share your profile and policy configurations?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 22:36:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/advanced-wildfire-allowing-high-severity-verdicts-but-blocking/m-p/575915#M2576</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-02-04T22:36:46Z</dc:date>
    </item>
  </channel>
</rss>

