Wildfire - Connection hold

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Wildfire - Connection hold

L4 Transporter

Hi all,

 

Just a question:

 

I didn't understand Wildfire mechanism related to a single session.

Is there a connection hold when waiting for a response (benign, malicious) from PA cloud by default? Is that configurable?

If the answer is Yes, but where?

 

Best Regards

Luca A. Di Leo

1 accepted solution

Accepted Solutions

Hi @TheRealDiz

 

that's right, thre is no holding mechanism pending a verdict

 

i looked it up and there is already a feature request : FR2833

please reach out to your local sales team and have them add your vote 🙂

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Hi @TheRealDiz

 

no the session is not held

if a file is received one of 3 actions can happen

 

file known malicious: blocked based on signature that was created prior

file known benign: file is passed through, benign logging is added (if benign logging is enabled)

file unknown: session is allowed to pass, file is grabbed and uploaded to WildFire for analysis, file is analysed and afterward the verdict is attached to the logging. if malicious: signature is created and rolled out to all WildFire customers

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi @reaper,

 

You are always on point, thanks a lot for your quick response.

So in conclusion, is this mechanism not configurable?

 

Thanks again

Luca

 

Hi @TheRealDiz

 

that's right, thre is no holding mechanism pending a verdict

 

i looked it up and there is already a feature request : FR2833

please reach out to your local sales team and have them add your vote 🙂

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Many Many thanks,

 

Infact I didn't find anything related to this argument inside Wildfire's documentation.

 

Have nice day! 🙂

  • 1 accepted solution
  • 2374 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!