<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75073#M41871</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The forward option in fileblocking (i'm assuming you're on 6.1) is technically an 'allow and log' option in the fileblocking portion and a forward option in the WildFire portion: The file is allowed to pass through and while it goes through the firewall, it collects&amp;nbsp;all the packets that make up the file and once complete sends it off to WildFire for analysis. (if it is found to be malicious a signature is created that is then send to the firewall in the form of an AV signature)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When 'block' is selected as action, the fileblocking will kick in and halt any file that matches the policy, but the file will no longer be forwarded to WildFire (as it has been blocked)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
    <pubDate>Wed, 23 Mar 2016 08:36:43 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-03-23T08:36:43Z</dc:date>
    <item>
      <title>Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75058#M41867</link>
      <description>&lt;P&gt;So currently I am using wildfire but only choosing to forward the file. Is anyone using the block option? If so are what are the pros and cons?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 18:18:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75058#M41867</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-03-22T18:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75059#M41868</link>
      <description>&lt;P&gt;Block?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Isn't that only an option for a "file blocking" policy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought it was in version 7.0.X where the decoupled fileblocking with WF. &amp;nbsp;So in 7.0.X on WF has it's own policy and the only options I see really are upload/download directionality and where the WF analysis would be.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 18:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75059#M41868</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-03-22T18:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75073#M41871</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The forward option in fileblocking (i'm assuming you're on 6.1) is technically an 'allow and log' option in the fileblocking portion and a forward option in the WildFire portion: The file is allowed to pass through and while it goes through the firewall, it collects&amp;nbsp;all the packets that make up the file and once complete sends it off to WildFire for analysis. (if it is found to be malicious a signature is created that is then send to the firewall in the form of an AV signature)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When 'block' is selected as action, the fileblocking will kick in and halt any file that matches the policy, but the file will no longer be forwarded to WildFire (as it has been blocked)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 08:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75073#M41871</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-03-23T08:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75089#M41875</link>
      <description>&lt;P&gt;Well its seems like you loose the longterm benefit of the information coming back to you in the threat prevention but get an immediate gain of it being blocked. Hard to decide which way to go&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 12:43:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75089#M41875</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-03-23T12:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75090#M41876</link>
      <description>&lt;P&gt;Yup you can choose block instead of forward&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 12:44:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75090#M41876</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-03-23T12:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75094#M41877</link>
      <description>&lt;P&gt;Both options have their merits&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The block option will block all files of a certain type;&amp;nbsp;filetypes that are unwanted in an organization can simply all be blocked, no matter what the content&lt;/P&gt;
&lt;P&gt;The forward option allows for users to download files while you get the files scanned for nasties. Once a nasty has been identified further downloads will be blocked by AV and you will be informed about an infection&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 13:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75094#M41877</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-03-23T13:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75099#M41879</link>
      <description>&lt;P&gt;Very hard to choose though the best practices from PA for os 6.1 suggest blocking for wildfire on the PE. I am using the "free" version of wild fire that only works for PE's&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 14:28:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75099#M41879</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-03-23T14:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75101#M41881</link>
      <description>&lt;P&gt;the big question: are your users supposed to download executables (PE), which means they could be installing software on their computers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if no: block&lt;/P&gt;
&lt;P&gt;if yes: all of them, or just the IT guys?&lt;/P&gt;
&lt;P&gt;you can still create policy that blocks PE downloads for most users but allows, and forwards, it for the IT group for example&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd personally prefer my userbase not to be downloading random software from the internet and provide them with the tools they need through my IT system, but that is not always an option (policy may contradict my wishes, or resource restrictions may prevent this mode of operation)&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 14:37:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire/m-p/75101#M41881</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-03-23T14:37:38Z</dc:date>
    </item>
  </channel>
</rss>

