<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: email attachment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/255065#M72389</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have couple of confusions here, could you please help.&lt;/P&gt;&lt;P&gt;Which database firewall will check for these URLs in email ?. is it PAN-DB ?. if yes, hope i need PAN-DB licence to have link analysis work properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So as you mentioned, when one url previously identified as malicious is available in another mail to differenr reciever, the mail will be blocked?.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 13:57:52 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2019-03-26T13:57:52Z</dc:date>
    <item>
      <title>email attachment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246050#M70093</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can anyone clear my following doubts.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have a mail server behind my PA, i am not doing ssl for mailserver communications.&lt;/LI&gt;&lt;LI&gt;i have antivirus &amp;amp; wildfire profiles applied for inbound and outbound connections to this mail server.&lt;/LI&gt;&lt;LI&gt;what if i get a mail to my server having malicious url inside mail( PA allready knows it as malicious, hope othervise he send to wildfire for analysis and update PAN-DB) , will PA block email?&lt;/LI&gt;&lt;LI&gt;what if i have URL as attachment ( encoded as pdf and attached to email) ?,&lt;/LI&gt;&lt;LI&gt;will antivirus profile will check URL aswell as he checks other file type?.&lt;/LI&gt;&lt;LI&gt;is there any difference if it was a phishing link or a download link ?&lt;/LI&gt;&lt;LI&gt;i understand if user clicks the url, he will be blocked as i have url filtering from inside to outside, (my concern is if he is outside network, not using GP nd access the site, his machine/credentials will be compromised.)&lt;/LI&gt;&lt;LI&gt;Is there a way for making PA to check email-link reputation with DB before the email send to user, if DB doesnt categorised the URL, email should go to user as wildfire will take time.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 09:22:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246050#M70093</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-01-15T09:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: email attachment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246355#M70162</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;What if i get a mail to my server having malicious url inside mail( PA allready knows it as malicious, hope othervise he send to wildfire for analysis and update PAN-DB) , will PA block email?&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, PA will block the email and if the URL is not known it will be sent to WF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;what if i have URL as attachment ( encoded as pdf and attached to email) ?,&lt;/LI&gt;&lt;LI&gt;will antivirus profile will check URL aswell as he checks other file type?.&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;PA will not check these URLs. It will only block the email if the attachment itself contains a virus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;is there any difference if it was a phishing link or a download link ?&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;PA will only block (if you configure it to) emails that contain phishing, malware and c&amp;amp;c URLs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;I understand if user clicks the url, he will be blocked as i have url filtering from inside to outside, (my concern is if he is outside network, not using GP nd access the site, his machine/credentials will be compromised.&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, without the firewall the users are obviously not protected by PA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Is there a way for making PA to check email-link reputation with DB before the email send to user, if DB doesnt categorised the URL, email should go to user as wildfire will take time.&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;No, not yet. This is in my opinion a job for an email gateway and not for a firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 20:25:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246355#M70162</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-16T20:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: email attachment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246431#M70174</link>
      <description>&lt;P&gt;Thanks vsys_remo&lt;SPAN class=""&gt;&amp;nbsp;for your kind support.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I am bit confused between first and Last answer, is in't it conflicting ?.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Just need to know whether PA will be blocking email if email body contains malicious/Phishing URL before the email reaches the reciever. PA will know about the url if he checks url DB only right?. i understand these all are email gateways job. But feels like, because these are technically possible, may PA is doing this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 07:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246431#M70174</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-01-17T07:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: email attachment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246531#M70188</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, your paloalto firewall will block these emails if the URLs are known malicious/phishing URLs. Unknown ones will be forwarded to wildfire bjt the email will also be forwarded even if wildfire decides this is a phishing URL. Mainly this is because the paloalto firewall is only stream based so it does what it can (which is already a lot) without storing data on the firewall while an email gateway is working store-and-forward. So it takes the email, does all the configured checks for malware and in some cases also URL reputation checks and if everything is good, then the email will be forwarded.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 19:18:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246531#M70188</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-17T19:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: email attachment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246532#M70189</link>
      <description>Thanks vsys_remo,&lt;BR /&gt;Your knowledge is much appreciated..</description>
      <pubDate>Thu, 17 Jan 2019 19:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/246532#M70189</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-01-17T19:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: email attachment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/255065#M72389</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have couple of confusions here, could you please help.&lt;/P&gt;&lt;P&gt;Which database firewall will check for these URLs in email ?. is it PAN-DB ?. if yes, hope i need PAN-DB licence to have link analysis work properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So as you mentioned, when one url previously identified as malicious is available in another mail to differenr reciever, the mail will be blocked?.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 13:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-attachment/m-p/255065#M72389</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-03-26T13:57:52Z</dc:date>
    </item>
  </channel>
</rss>

