<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why pdf file action is forward on wildfire? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25526#M18624</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Are all files(ppt , jpg etc..) forwarded from data-plane to management-plane?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;- If&amp;nbsp; a file download session matches an AV profile enabled to the security rule, then file will be streamed to Content-ID engine for AV scanning. If not, only then the file is is streamed from the dataplane to the management plane for wildfire processing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;cancel_disk_io_fail counter:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Number of times the management plane failed to write temporary files to the disk before sending them to the WildFire cloud.&amp;nbsp; This can occur with a general disk fault, and can also occur when the disk buffer is near quota.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I did read in an internal document that apparently the counter would only show up in wildfire statistics if it is non-zero.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks and regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Kunal Adak&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Nov 2013 15:05:35 GMT</pubDate>
    <dc:creator>kadak</dc:creator>
    <dc:date>2013-11-12T15:05:35Z</dc:date>
    <item>
      <title>Why pdf file action is forward on wildfire?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25523#M18621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;I am seeing data-filtering logs for wildfire and have found some logs.&lt;/P&gt;&lt;P&gt;It is pdf file log that action is forward.&lt;/P&gt;&lt;P&gt;Wildfire configuration is any application and action forward.&lt;/P&gt;&lt;P&gt;But PDF is not PE file.&lt;/P&gt;&lt;P&gt;I don't understand Why pdf file action is forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;forward&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Data plan detected a PE file on a WildFire-enabled policy.&amp;nbsp; The PE file is buffered in management plane.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;At this point, if you only see "forward" for a specific file, then that means it is either signed by a trusted file signer, or it is a benign sample that the cloud has already seen.&amp;nbsp; In either case, no further action is performed on the file, and no further information is sent to the cloud (not even session information is sent for previously seen benign files).&amp;nbsp; &lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;This means that you will not see an entry in the WildFire web portal for these files.&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;I think reason that t&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;he data plan detected any file on a wildfre-enabled policy and the any file is buffered in management plan because wildfire configuration is any file. Right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I know only PE file was forward when wildfire configuration is any file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 07:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25523#M18621</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-11-11T07:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why pdf file action is forward on wildfire?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25524#M18622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you are right. Since you have configured 'any' file type in file blocking profile you would get a data-filtering log as 'forward' for all file downloads - atleast.&amp;nbsp; PE is just a file format category which includes file types with extensions exe,zip..etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If an AV profile is not enabled on a firewall policy for an existing session, the file is streamed from dataplane to management plane for Wildfire processing. That file is&amp;nbsp; then received by the end user and buffered by the management plane. If the file is signed by a trusted signer, the file download gets logged in the data-filtering logs with action set to 'forward' and&lt;STRONG&gt; no entry is logged in wildfire web portal&lt;/STRONG&gt;. If the file is not signed by the trusted signer, then the management plane creates a hash of file to send it to the Wildfire cloud to run a check against existing signatures in the database. From there on, depending upon whether the hash match exists in the database or not, the corresponding data-filtering log gets marked as 'wildfire-upload-skip' or 'wildfire-upload-success'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that addresses your concern!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;BR /&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 18:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25524#M18622</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-11T18:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why pdf file action is forward on wildfire?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25525#M18623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Adak,&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;I have a more detail question.&lt;/P&gt;&lt;P&gt;I use wildfire configuration that action for all files is forward.&lt;/P&gt;&lt;P&gt;Are all files(ppt , jpg etc..) forwarded from data-plane to management-plane?&lt;/P&gt;&lt;P&gt;If it is true, I think management-plane buffer allocated wildfire will be very hard.&lt;/P&gt;&lt;P&gt;If buffer will be overflow what value on 'show wildfire statistics' will be increased??&lt;/P&gt;&lt;P&gt;I read manual that if buffer will be&amp;nbsp; overflow cancel_disk_io_fail on 'show wildfire statistics' will be increased.&lt;/P&gt;&lt;P&gt;But I have found it on this cli output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 12:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25525#M18623</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-11-12T12:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why pdf file action is forward on wildfire?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25526#M18624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Are all files(ppt , jpg etc..) forwarded from data-plane to management-plane?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;- If&amp;nbsp; a file download session matches an AV profile enabled to the security rule, then file will be streamed to Content-ID engine for AV scanning. If not, only then the file is is streamed from the dataplane to the management plane for wildfire processing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;cancel_disk_io_fail counter:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Number of times the management plane failed to write temporary files to the disk before sending them to the WildFire cloud.&amp;nbsp; This can occur with a general disk fault, and can also occur when the disk buffer is near quota.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I did read in an internal document that apparently the counter would only show up in wildfire statistics if it is non-zero.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks and regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Kunal Adak&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 15:05:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pdf-file-action-is-forward-on-wildfire/m-p/25526#M18624</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-12T15:05:35Z</dc:date>
    </item>
  </channel>
</rss>

