- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
03-30-2017 03:47 PM
Hello
I am testing my wildfire configuration .
1- When I download wildfire test PE file , I get an entry under Wildfire submission log & data filtering log.
2- I intend to test if copying the PE file is also caught by wildfire , so I download a new PE file from wildfire site on a machine that is not protected by wildfire , then copy it across to a machine in another zone . the rule has wildfire and block file . this time we do not get any submission but we see a record under data-filtering.
why there is no wild fire submissions in this case ?
in first approach , the application is web-browsing
second approach , the application is ms-ds-smb
Is it possible that some applications are excluded from wildfire ? it seems only Risk5 apps are being sent . is there a place to change the behavior ?
03-30-2017 11:13 PM
Check the threat logs for AV events. File is sent to WF only when WF doesn't know that file yet. If WF has already seen that file it only replies with verdict or apropriate signature, there's no need to upload file again.
03-31-2017 12:05 AM
"the rule has wildfire and block file"
are you blocking the file copy? a blocked session will not be uploaded to wildfire as the file is never completely transferred
03-31-2017 05:43 AM - edited 03-31-2017 05:54 AM
FYI,
Your not going to see a submission log for something that has already been identified since your local firewall database already knows about the file, that's why the wildfire test PE is generated per request so that you actually see a submission log. If you are copying an already identified known bad file it can skip the submission process and simply take action based on what it already knows about the file.
**EDIT**
and @santonic already mentioned this...my bad
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!