What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?

L2 Linker

Hi;

 

My understanding is that the PAN OS performs a hash of the file, then checks with Wildfire to see if this file has been seen or not. If it has not been seen, then it performs an AV scan on it to determine if it matches a known signature. If the file does not match any known signature, then and only then it gets sent to Wild-Fire public or private cloud for sandboxing.

 

Please comment if you can.

 

Kindly

Wasfi

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

On-firewall AV scanning is done in transit, so bytes go through the firewall and bytes get scanned

If at any point during the flow a malicious signature is detected the flow is interrupted and the file transfer stopped

Only if the on-device scan does not block a file this way, will we be able to get to the end of the file and collect a hash to check with wildfire if the file has already been uploaded or not.

if the file has not been seen yet, it is uploaded and put in a sandbox

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

Since march 2018 even files that match an AV signature will be forwarded to wildfire: https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/wil...

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

On-firewall AV scanning is done in transit, so bytes go through the firewall and bytes get scanned

If at any point during the flow a malicious signature is detected the flow is interrupted and the file transfer stopped

Only if the on-device scan does not block a file this way, will we be able to get to the end of the file and collect a hash to check with wildfire if the file has already been uploaded or not.

if the file has not been seen yet, it is uploaded and put in a sandbox

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Since march 2018 even files that match an AV signature will be forwarded to wildfire: https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/wil...

  • 2 accepted solutions
  • 2415 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!