- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-05-2015 11:14 AM
Hello,
i setup wildfire to forward any application, any files so wildfire could test files against malware.
I discovered that ms-office files are not sent to wildfire.
File blocking rule is set to any/any/both/forward
Antivirus rule is set to block on wildfire for http/smtp/ftp
Antivirus rule is set to policy rule.
Despite of this i can upload/download malware .doc file either in ftp or smtp
PA-3020 PAN-OS 6.1.2
03-05-2015 11:40 AM
Hi CRA,
Lets say if its a brand new malware and first time firewall got its signature. Than following sequence of actions happens.
1. Firewall buffers file
2. Compares its MD5 signature against
3. Its a brandnew MD5 so friewall send firewall to wildfire for dianosis.
4. Wildfire dettermins its a malware
5. Pushed updates to "wildfire license" enabled machines in next 30 minutes.
6. Update is installed in anti-virus.
7. Now firewall will block the file.
Let me know which event is not working.
Regards,
Hardik Shah
03-06-2015 12:57 AM
Hi Hardik,
i'm fine on the wildfire process, but still have some problems.
I setup wildfire submission as described in my previous message, but in data filtering log, msoffices files (for example) list an action "alert". What does it means ?
03-06-2015 01:08 AM
Hello CRA,
Could you please let me know if you have configured any "file blocking" profile in the security policy. The file blocking profile might be set the action to "alert" for ms files.
The wildfire should show action as forward” “wildfire-upload-success” or “wildfire-upload-skip”. Refer below document for more detail:
Hope this helps.
Thanks
03-06-2015 01:24 AM
Hello Hulk,
File blocking profile is set to the profile "wildfire" i created.
Profile is this one
03-06-2015 02:34 AM
are those really .doc files or .docx?
.docx files are detected as zip files because they are decrypted. Could you update your File Blocking Profile and add zip to the file types?
03-06-2015 08:26 AM
Files are doc files.
msoffice type does not includes docx or xlsx files ?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!