Friewall does not send ms-files to wildfire

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Friewall does not send ms-files to wildfire

L1 Bithead

Hello,

i setup wildfire to forward any application, any files so wildfire could test files against malware.

I discovered that ms-office files are not sent to wildfire.

File blocking rule is set to any/any/both/forward

Antivirus rule is set to block on wildfire for http/smtp/ftp

Antivirus rule is set to policy rule.

Despite of this i can upload/download malware .doc file either in ftp or smtp

PA-3020 PAN-OS 6.1.2

6 REPLIES 6

L6 Presenter

Hi CRA,

Lets say if its a brand new malware and first time firewall got its signature. Than following sequence of actions happens.

1. Firewall buffers file

2. Compares its MD5 signature against

3. Its a brandnew MD5 so friewall send firewall to wildfire for dianosis.

4. Wildfire dettermins its a malware

5. Pushed updates to "wildfire license" enabled machines in next 30 minutes.

6. Update is installed in anti-virus.

7. Now firewall will block the file.

Let me know which event is not working.

Regards,

Hardik Shah

Hi Hardik,

i'm fine on the wildfire process, but still have some problems.

I setup wildfire submission as described in my previous message, but in data filtering log, msoffices files (for example) list an action "alert". What does it means ?

L7 Applicator

Hello CRA,

Could you please let me know if you have configured any "file blocking" profile in the security policy. The file blocking profile might be set the action to "alert" for ms files.

The wildfire should show action as forward”  “wildfire-upload-success” or “wildfire-upload-skip”. Refer below document for more detail:

How to Configure WildFire

Hope this helps.

Thanks

Hello Hulk,

File blocking profile is set to the profile "wildfire" i created.

Profile is this one

blocking_profile.jpg

are those really .doc files or .docx?

.docx files are detected as zip files because they are decrypted. Could you update your File Blocking Profile and add zip to the file types?

Files are doc files.

msoffice type does not includes docx or xlsx files ?

  • 3123 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!