Wildfire Double Ring - Perimetral Network External / Internal

Reply
Highlighted
L4 Transporter

Wildfire Double Ring - Perimetral Network External / Internal

Hello, :smileyinfo:

We have a double ring structure and we are trying to implement the most appropriate settings for the Wildfire, according to the scenario that we have.

Wildfire.jpeg

-A Cluster 2 firewalls External *OUT*

  Model PA-500

  WildFire Version 52587-59292 (02/02/15)

salida file blocking profile.jpg

-A Cluster 2 firewalls Internal *IN

  Model PA-2050

  WildFire Version 52588-59293 (02/03/15)

file blocking profile.jpg

Data Filtering.jpg

Logs -> Wildfire Submissions

Why we don't see anything in Wildfire Submissions?

What settings can you recommand me?

To perform an analysis. How could we do this?

  • A monthly report by wildfire scanned files with malware verdict.
  • A monthly report with the Top of machines that are connected to dangerous sites.
  • A monthly report with the Top dangerous sites.
  • A monthly report with the machines that are trying to download files and analyzed with malware verdict.

Regards,

Diego C.


Accepted Solutions
Highlighted
L7 Applicator

Hello Diego,

Could you please check what action has been set on your file-blocking profile, it should be "forward" or "continue-and-forward" to send the file to wildfire cloud for analysis.

forward—The file is automatically sent to WildFire.

continue-and-forward—A continue page is presented, and the file is sent to WildFire (combines the continue and forward actions). This action only works with web-based traffic. This is due to the fact that a user must click continue before the file will be forward and the continue response page option is only available with http/https.

Thanks

View solution in original post


All Replies
Highlighted
L7 Applicator

Hello Diego,

You may follow this doc to understand different settings for wildfire: How to Configure WildFire

FYI..

How to Generate a Custom Report for Wildfire Logs

Thanks

Highlighted
L7 Applicator

Hello Diego,

Could you please check what action has been set on your file-blocking profile, it should be "forward" or "continue-and-forward" to send the file to wildfire cloud for analysis.

forward—The file is automatically sent to WildFire.

continue-and-forward—A continue page is presented, and the file is sent to WildFire (combines the continue and forward actions). This action only works with web-based traffic. This is due to the fact that a user must click continue before the file will be forward and the continue response page option is only available with http/https.

Thanks

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!