why do we update wf-content-version on WF-500 appliance

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

why do we update wf-content-version on WF-500 appliance

L3 Networker

Dear Experts,

 

I was wondering that why do we update wf-content-version on WF-500 appliance, what is the reason for it. As I have configured WF-500 to generate the signature locally, what additional value will be added by downloading why do we update wf-content-version on WF-500 appliance.

 

Best Regards,

 

Fozail

6 REPLIES 6

Cyber Elite
Cyber Elite

Hi Fozail

 

The WF updates contain signatures created by analyzing files from other locations (and other customers)

Someone else may have received an infected file before you and a signature created. This means you no longer need to dedicate CPU cycles to investigate a file if a verdict and signature is already available

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi, 

 

I hope WF update is different than "wf-content-version" update.

 

I agree with you that WF updates contain signatures created by analyzing files from other locations (and other customers), but this update will be taken care by firewall who got the WildFire license.

 

But my question is why do we update "wf-content-version" on WF-500 appliance?

 

Best Regards,

 

Fozail

sss.PNG

Hi,

 

I have seen this information in the admin guide, but it does not tell that WF-500 appliance will get a threat data base or hash database along with wf-content-version, as WF-500 should perform two function primarily:-

 

1) match the hash sent by the PA firewall, it it is in the database tell what is the verdict.

2) If hash was not matched PA firewall should upload file and session information to WF-500 appliance, it should be run and analyzed here for the verdict/behaviour.

 

So where do we see the advanatge of updating wf-content-version?

 

Best Regards,

 

Fozail

well, 2. is pretty compelling 🙂

 

1) things already scanned elsewhere do not need to be rescaned, verdict immediately available (in case the firewall is not aware yet)

2) scanning engine updates making your scanning engines better and results more accurate

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

It's crystal clear now 🙂 

  • 3377 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!