- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-09-2019 08:57 PM - edited 04-09-2019 08:58 PM
Hi;
My understanding is that the PAN OS performs a hash of the file, then checks with Wildfire to see if this file has been seen or not. If it has not been seen, then it performs an AV scan on it to determine if it matches a known signature. If the file does not match any known signature, then and only then it gets sent to Wild-Fire public or private cloud for sandboxing.
Please comment if you can.
Kindly
Wasfi
04-09-2019 10:29 PM
On-firewall AV scanning is done in transit, so bytes go through the firewall and bytes get scanned
If at any point during the flow a malicious signature is detected the flow is interrupted and the file transfer stopped
Only if the on-device scan does not block a file this way, will we be able to get to the end of the file and collect a hash to check with wildfire if the file has already been uploaded or not.
if the file has not been seen yet, it is uploaded and put in a sandbox
04-09-2019 11:00 PM
Since march 2018 even files that match an AV signature will be forwarded to wildfire: https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/wil...
04-09-2019 10:29 PM
On-firewall AV scanning is done in transit, so bytes go through the firewall and bytes get scanned
If at any point during the flow a malicious signature is detected the flow is interrupted and the file transfer stopped
Only if the on-device scan does not block a file this way, will we be able to get to the end of the file and collect a hash to check with wildfire if the file has already been uploaded or not.
if the file has not been seen yet, it is uploaded and put in a sandbox
04-09-2019 11:00 PM
Since march 2018 even files that match an AV signature will be forwarded to wildfire: https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/wil...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!