How to Add custom file extensions in PA file extension list?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How to Add custom file extensions in PA file extension list?

L1 Bithead

Hello,

 

         As we are implemeting Paloalto NGFW 3020 in our organization and now we facing a problem. We are implemeting security profiles and we want to add some file extensions which is not listed in PA file extension list. How could we add these custom file extensions such as *.vb, *.vbs, *.com etc...? Very appreciate for all of your valuable supports.

1 REPLY 1

Community Team Member

Hi @Wayne88,

 

Palo Alto Networks firewalls don't block based on file extensions but rather on file types.  The file blocking profile is “type” based and decoders are used to identify the file type, not the file's extension.

 

If your file name is long enough you could use a custom signature for a match but a minimum of 7 bytes is required so I'm guessing this won't work for you.

 

There's already a feature request for this (ID 668) where customers would like to see the fileblocking ability enhanced by allowing for a block to be defined based on a filename as well as file extension as an option.  To add your vote to this FR I suggest that you reach out to your local SE.

 

Cheers !

-K

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 3044 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!