<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire .docx in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74277#M41650</link>
    <description>&lt;P&gt;After changing the file blocking profile to "file typ: any" it seems that .docx are now forwarded to the wildfire cloud...maybe a problem with identifying .docx files ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2016 15:34:03 GMT</pubDate>
    <dc:creator>iweltag</dc:creator>
    <dc:date>2016-03-07T15:34:03Z</dc:date>
    <item>
      <title>Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74122#M41614</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i am testing wildfire at the moment for forwarding .doc, .docx and EXE Files to the wildfire cloud.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is my rule:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2925i58294C4B6AB88C3E/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="WF Rule" title="WF Rule" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But it seems, that only .doc and .exe Files are forwared to the cloud (first Forward but then upload skip because the cloud have already seen this file - that´s ok)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The .docx files are just in "alert" state and will not be forwarded to the cloud . Does anybody know why?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2926i20D29AD998F66FE9/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="DF Log" title="DF Log" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 09:57:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74122#M41614</guid>
      <dc:creator>iweltag</dc:creator>
      <dc:date>2016-03-04T09:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74145#M41620</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The most probable reason why it is just reporting 'Alert' is that the file has already been seen by wildfire at some point and it benign.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try creating a custom DOCX and see what happens.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 14:18:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74145#M41620</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-03-04T14:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74158#M41624</link>
      <description>&lt;P&gt;Is the docx file downloaded inside a https connection? To upload decrypted to Wildfire there is an extra setting to enable this.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 18:19:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74158#M41624</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2016-03-04T18:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74207#M41635</link>
      <description>&lt;P&gt;Yes i have already configured "forwarding decrypted files". Decrypting policy is also configured. I will try this on monday with an own created docx file and see what happen.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Mar 2016 12:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74207#M41635</guid>
      <dc:creator>iweltag</dc:creator>
      <dc:date>2016-03-05T12:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74269#M41648</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it does not work when i am using an own created .docx file. i can not see any upload in the logfile. just alert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2977i2771A35F21670715/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="docx" title="docx" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2978iD46B4E827617D3D4/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="detail log" title="detail log" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 11:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74269#M41648</guid>
      <dc:creator>iweltag</dc:creator>
      <dc:date>2016-03-07T11:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74277#M41650</link>
      <description>&lt;P&gt;After changing the file blocking profile to "file typ: any" it seems that .docx are now forwarded to the wildfire cloud...maybe a problem with identifying .docx files ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 15:34:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74277#M41650</guid>
      <dc:creator>iweltag</dc:creator>
      <dc:date>2016-03-07T15:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74395#M41679</link>
      <description>&lt;P&gt;Hi Iweltag,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was going to respond to your message but than did not have firewall with lesser PAN-OS than 7.x to check if I am correct &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; sorry I didn't, I feel like coming late to the party now. Anyways:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you could either add zip filetype or ms-office (not sure if that exists as such in 6.x) along with .doc filetype; fact is that there is a big difference in fileformats where .doc is closed file format and if I remember well should have magic number "D0C F11E" - doc file; while docx is actually an archive containing more files and you can open office xlsx or docx and such files with unarchiver app.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would try adding doc and zip filetypes to your file blocking profile to check if that will work, and if you have ms-office try that filetype as well instead of any. Otherwise, if docx was selectable but not working as expected I would open a case with TAC to check and to bring the issue to their attention.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 19:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74395#M41679</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-03-08T19:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74425#M41683</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your respond. I will try that and give you a feedback :)...&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 08:25:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74425#M41683</guid>
      <dc:creator>iweltag</dc:creator>
      <dc:date>2016-03-09T08:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74444#M41690</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when i am using "microsoft-office" as the filetype to be forwarded to the cloud it seems to work fine with .docx files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also find this hint on PAN Help:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[...]&lt;/P&gt;
&lt;P&gt;If you want the firewall to block/forward MS Office files, it is recommended that you select this “msoffice” group to ensure all supported MS Office file types will be identified instead of selecting each file type individually.&lt;/P&gt;
&lt;P&gt;[...]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i am using "docx, gzip, zip" file type in the data blocking policy the docx files will not be forwarded to the cloud.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 13:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74444#M41690</guid>
      <dc:creator>iweltag</dc:creator>
      <dc:date>2016-03-09T13:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74468#M41701</link>
      <description>&lt;P&gt;Hi Iweltag,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am glad advice still had some value &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;ok, so it will work with ms-office. I would think it should work with docx but "your mileage may wary" depending on the particular docx and perhaps of what it embeds, so I would still go for ms-office filetype. If this creates a problem for you (for example, you wanted exclusively docx forwarded but not the rest) you should still open the case with TAC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 18:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/74468#M41701</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-03-09T18:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire .docx</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/124685#M46355</link>
      <description>&lt;P&gt;I ran into this issue as well and found that we had an old file blocking profile that alerted on ZIP file downloads.&amp;nbsp; This was making the Palo tag them as ZIP instead of MS-Office files.&amp;nbsp; I removed that from the file blocking profile and now they get detected as MS-Office and now get submitted to Wild Fire.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 16:46:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-docx/m-p/124685#M46355</guid>
      <dc:creator>Rich_G</dc:creator>
      <dc:date>2016-11-07T16:46:40Z</dc:date>
    </item>
  </channel>
</rss>

