- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-14-2016 10:35 PM
Dear Experts,
I was wondering that why do we update wf-content-version on WF-500 appliance, what is the reason for it. As I have configured WF-500 to generate the signature locally, what additional value will be added by downloading why do we update wf-content-version on WF-500 appliance.
Best Regards,
Fozail
12-15-2016 12:08 AM
Hi Fozail
The WF updates contain signatures created by analyzing files from other locations (and other customers)
Someone else may have received an infected file before you and a signature created. This means you no longer need to dedicate CPU cycles to investigate a file if a verdict and signature is already available
12-15-2016 06:15 AM
Hi,
I hope WF update is different than "wf-content-version" update.
I agree with you that WF updates contain signatures created by analyzing files from other locations (and other customers), but this update will be taken care by firewall who got the WildFire license.
But my question is why do we update "wf-content-version" on WF-500 appliance?
Best Regards,
Fozail
12-15-2016 06:56 AM
Hi,
I have seen this information in the admin guide, but it does not tell that WF-500 appliance will get a threat data base or hash database along with wf-content-version, as WF-500 should perform two function primarily:-
1) match the hash sent by the PA firewall, it it is in the database tell what is the verdict.
2) If hash was not matched PA firewall should upload file and session information to WF-500 appliance, it should be run and analyzed here for the verdict/behaviour.
So where do we see the advanatge of updating wf-content-version?
Best Regards,
Fozail
12-15-2016 07:07 AM
well, 2. is pretty compelling 🙂
1) things already scanned elsewhere do not need to be rescaned, verdict immediately available (in case the firewall is not aware yet)
2) scanning engine updates making your scanning engines better and results more accurate
12-15-2016 07:16 AM
It's crystal clear now 🙂
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!