<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire block confusion in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/212495#M325</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have some queries regarding this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the Firewall didn't have the Threat id,&amp;nbsp; the mail or the Traffic was allowed to pass through to the destination?&lt;/P&gt;&lt;P&gt;And the severity is high because we didn't have a Threat-id for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And we see the verdict as malicious but the traffic action is allow.&lt;/P&gt;&lt;P&gt;This means the verdict was done by the Public cloud wildfire after the traffic which has been allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 May 2018 19:54:56 GMT</pubDate>
    <dc:creator>sprasad</dc:creator>
    <dc:date>2018-05-01T19:54:56Z</dc:date>
    <item>
      <title>Wildfire block confusion</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/197996#M188</link>
      <description>&lt;P&gt;All 3 are using same antivirus profile.&amp;nbsp; While the informational shows as block, high shows as allow. Its only for smtp that .exe&amp;nbsp;files are&amp;nbsp;set to be blocked. All is set to drop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13565iD74D2B0339D4DBA4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 19:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/197996#M188</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-01-31T19:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire block confusion</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/197998#M189</link>
      <description>&lt;P&gt;Wildfire submissions with a corresponding action of "block" are considered to be informational severity alerts given that the threat was successfully blocked.&amp;nbsp; You should see a corresponding Threat Log which logged the block for this file with either a threat type of "wildfire-virus" or "virus".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Wildfire submissions with a corresponding action of "allow" are considered to be&amp;nbsp;high severity alerts given that the threat was allowed (i.e. no Threat ID existed at the time of detection to block the malicious file).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 19:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/197998#M189</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-01-31T19:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire block confusion</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/212495#M325</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have some queries regarding this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the Firewall didn't have the Threat id,&amp;nbsp; the mail or the Traffic was allowed to pass through to the destination?&lt;/P&gt;&lt;P&gt;And the severity is high because we didn't have a Threat-id for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And we see the verdict as malicious but the traffic action is allow.&lt;/P&gt;&lt;P&gt;This means the verdict was done by the Public cloud wildfire after the traffic which has been allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 19:54:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/212495#M325</guid>
      <dc:creator>sprasad</dc:creator>
      <dc:date>2018-05-01T19:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire block confusion</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/212699#M326</link>
      <description>&lt;P&gt;Yes. To&amp;nbsp;the one question.&amp;nbsp;And I confirm your statements. That's correct.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 17:02:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/212699#M326</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-05-02T17:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire block confusion</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/229422#M393</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I block traffic until the verdict of Wildfire? Is there a way to do it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 18:18:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-block-confusion/m-p/229422#M393</guid>
      <dc:creator>diegostny</dc:creator>
      <dc:date>2018-09-04T18:18:32Z</dc:date>
    </item>
  </channel>
</rss>

