- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
03-18-2013 01:42 PM
Hello,
I currently have a security rule that blocks the downloads of ".exe" files from the "unknown" URL category (which sits above my general Internet/WildFire Forward rule). It works extremely well in dropping a huge amount of the garbage out there. However, occasionally the garbage makes it past that rule and sends up a WildFire event. Again, Deny rule comes before the WildFire forward. I noticed from the WildFire alert that in the cases of communication which appears to bypass the deny rule - the source and destination are actually reversed to what the rule is set. Instead of my user being the source - it is now the destination. Should my rule to deny the .exe also include a bidirectional zone?
Current Deny .exe rule
Source Zone - Internal
Destination Zone - External
Application - Web-Browsing
URL Category - "Unknown" (PANDB)
Profile - "DenyEXE" File blocking profile for .exe/download/block
Should my zones be a bidirectional setup to block anything that is coming inbound? I had hoped the user session would keep state of that? Should the File Blocking profile be both upload and download? Thanks!
Mike
04-08-2013 06:21 AM
It appears my resolution was that in my file blocking profile only had "download" for the direction. Modifying to "both" looks to have done the trick.
03-19-2013 06:18 AM
Want to add that if adding the bidirectional zone would be beneficial - it concerns me to add "external" source to "internal" destination in this case. How big a concern is that in this particular setup? We are NAT'd behind the external interface. Thanks.
04-08-2013 06:21 AM
It appears my resolution was that in my file blocking profile only had "download" for the direction. Modifying to "both" looks to have done the trick.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!