File types need to block

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

File types need to block

L2 Linker

The file type is malicious as per the swift advisory 2021, that need to be block on the Palo alto Firewall.

File Type .gmu,.ekt, .jpn,.er,

3 REPLIES 3

L2 Linker

Any solution is available on this .how to block on firewall.

Cyber Elite
Cyber Elite

Hello,

The PAN only know of certain filetypes. That said here are a few things to think about:

  • Only allow the file types the PAN knows?  Its a whitelist approach rather than a blacklist approach.
  • Enable all AV and Threat options including wildfire. This should block any known bad files and potentially new ones with wildfire. Also use secure DNS and URL filtering to prevent dropper loads.

Sorry its not a direct answer. Perhaps others may have other insights.

Regards,

Cyber Elite
Cyber Elite

@SurajN,

The firewall isn't the answer to all problems; it's relatively seamless to block the execution of file types on macOS, Linux, and Windows on managed endpoints. That's really the "answer" here instead of attempting to do it at the network level. Because the firewall file-blocking is type based and needs specific decoders, the capabilities there are limited. 

You could potentially try looking at custom threat signatures to see if they could potentially be used to rig something up, but last I looked this wasn't really a clear cut solution and wasn't accurately blocking files completely. 

 

 

  • 1951 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!