- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-03-2017 12:52 AM - edited 02-05-2017 06:30 PM
Hello,
As we are implemeting Paloalto NGFW 3020 in our organization and now we facing a problem. We are implemeting security profiles and we want to add some file extensions which is not listed in PA file extension list. How could we add these custom file extensions such as *.vb, *.vbs, *.com etc...? Very appreciate for all of your valuable supports.
02-03-2017 04:36 AM
Hi @Wayne88,
Palo Alto Networks firewalls don't block based on file extensions but rather on file types. The file blocking profile is “type” based and decoders are used to identify the file type, not the file's extension.
If your file name is long enough you could use a custom signature for a match but a minimum of 7 bytes is required so I'm guessing this won't work for you.
There's already a feature request for this (ID 668) where customers would like to see the fileblocking ability enhanced by allowing for a block to be defined based on a filename as well as file extension as an option. To add your vote to this FR I suggest that you reach out to your local SE.
Cheers !
-K
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!