<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic wildfire and security policy - problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51789#M38101</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have enabled wilfdire protection on polisy for NAT (also antyvirus/antyspyware/Volnerability).&lt;/P&gt;&lt;P&gt;From time totime I get email with information that someone from my network downloaded some files infected ie. by malware.&lt;/P&gt;&lt;P&gt;Until now I think that this file was blocked by PAN.&lt;/P&gt;&lt;P&gt;Today I tryed (just for test) download file from link from that email (storagenl.info/v402/?affiliate_id=eb3)&lt;/P&gt;&lt;P&gt;and I downloaded file .... and I got a email.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;File blocking profile is created with any any both forward settings. This profile is enabled in security policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me please&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Dec 2012 15:41:19 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2012-12-14T15:41:19Z</dc:date>
    <item>
      <title>wildfire and security policy - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51789#M38101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have enabled wilfdire protection on polisy for NAT (also antyvirus/antyspyware/Volnerability).&lt;/P&gt;&lt;P&gt;From time totime I get email with information that someone from my network downloaded some files infected ie. by malware.&lt;/P&gt;&lt;P&gt;Until now I think that this file was blocked by PAN.&lt;/P&gt;&lt;P&gt;Today I tryed (just for test) download file from link from that email (storagenl.info/v402/?affiliate_id=eb3)&lt;/P&gt;&lt;P&gt;and I downloaded file .... and I got a email.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;File blocking profile is created with any any both forward settings. This profile is enabled in security policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me please&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2012 15:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51789#M38101</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2012-12-14T15:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: wildfire and security policy - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51790#M38102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SLV,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless you have the new Wildfire subscription (PAN-OS 5.0) enabled you may need to wait a couple days for the actual virus signature to be pushed down to your device through the normal AV signature process.&amp;nbsp; With the Wildfire subscription you can get hourly updates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 03:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51790#M38102</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2012-12-17T03:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: wildfire and security policy - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51791#M38103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SLV, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you and file blocking profile with forward option. It will allow the files to be downloaded and the file will be sent to Wildfire for checking. This is default action it takes when the file blocking is set to forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 18:23:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51791#M38103</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2012-12-17T18:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: wildfire and security policy - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51792#M38104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thought that "forward" mean that PA200 will forward every file to WildFire cloud and after that if status recieved from WildFire Cloud is "clean" will allow to download to client workstation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to get such confoguration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 13:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51792#M38104</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2012-12-18T13:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: wildfire and security policy - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51793#M38105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Slawek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like that would create a delay too great for most clients. Part of what WildFire does is execute the file and observe the behavior along with normal signature and heuristic-based scans. If a client had to wait for that they would likely time out. You may want to reach out to your account team to suggest that feature in case it hasn't been submitted already.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer the question about the "forward" action, it:&lt;/P&gt;&lt;P&gt; - Delivers the file to the client&lt;/P&gt;&lt;P&gt; - Forwards it to WildFire for review&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have 5.0 and the additional license, you can download updates as often as every hour that will contain results of scans. If a file you (or another customer) has forwarded is malware, you'll have the signature for it within hours. Of course, as Kelly indicated you can still use the standard WildFire configuration to get updates every day so you'll have that signature within a day or two normally as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;Greg &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 17:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51793#M38105</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2012-12-18T17:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: wildfire and security policy - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51794#M38106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Forward does not mean that the file has been forwarded to the wildfire cloud !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Forward: The Wildfire cloud has already seen the file, thus no further action is taken on the file and no entry is seen on the wildfire portal.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Wildfire-upload-success: The Wildfire cloud has not seen the file and the file is uploaded to the cloud for a verdict.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Wildfire-upload-skip:&amp;nbsp; The Wildfire cloud has already seen the file and confirmed a verdict of "Malware" thus the file is skipped by the PA device, however a log is generated on the Wildfire portal&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Roland&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2013 07:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-and-security-policy-problem/m-p/51794#M38106</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-02-26T07:19:43Z</dc:date>
    </item>
  </channel>
</rss>

