Friewall does not send ms-files to wildfire

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L1 Bithead

Friewall does not send ms-files to wildfire

Hello,

i setup wildfire to forward any application, any files so wildfire could test files against malware.

I discovered that ms-office files are not sent to wildfire.

File blocking rule is set to any/any/both/forward

Antivirus rule is set to block on wildfire for http/smtp/ftp

Antivirus rule is set to policy rule.

Despite of this i can upload/download malware .doc file either in ftp or smtp

PA-3020 PAN-OS 6.1.2

Highlighted
L6 Presenter

Hi CRA,

Lets say if its a brand new malware and first time firewall got its signature. Than following sequence of actions happens.

1. Firewall buffers file

2. Compares its MD5 signature against

3. Its a brandnew MD5 so friewall send firewall to wildfire for dianosis.

4. Wildfire dettermins its a malware

5. Pushed updates to "wildfire license" enabled machines in next 30 minutes.

6. Update is installed in anti-virus.

7. Now firewall will block the file.

Let me know which event is not working.

Regards,

Hardik Shah

Highlighted
L1 Bithead

Hi Hardik,

i'm fine on the wildfire process, but still have some problems.

I setup wildfire submission as described in my previous message, but in data filtering log, msoffices files (for example) list an action "alert". What does it means ?

Highlighted
L7 Applicator

Hello CRA,

Could you please let me know if you have configured any "file blocking" profile in the security policy. The file blocking profile might be set the action to "alert" for ms files.

The wildfire should show action as forward”  “wildfire-upload-success” or “wildfire-upload-skip”. Refer below document for more detail:

How to Configure WildFire

Hope this helps.

Thanks

Highlighted
L1 Bithead

Hello Hulk,

File blocking profile is set to the profile "wildfire" i created.

Profile is this one

blocking_profile.jpg

Highlighted
L3 Networker

are those really .doc files or .docx?

.docx files are detected as zip files because they are decrypted. Could you update your File Blocking Profile and add zip to the file types?

Highlighted
L1 Bithead

Files are doc files.

msoffice type does not includes docx or xlsx files ?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!