- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-08-2015 07:10 AM
Hello, I have a general question about wildfire. We would like to have wildfire inspect email attachments and send suspect files to WF for scan and remediation. My question is....how does this work? Does the firewall hold the email and wait for a fix from wildfire before forwarding the email? If it does hold the email, what sort of delay does this add?
Is there a document that explains how WF works?
Thanks,
Bryan
07-08-2015 11:49 AM
Hey Skidoohead,
Let me lay out multiple scenarios for you.
1. The firewall has a local definition for the file in question.
- When the firewall is set to scan the supported file types, it will check the local database and compare the md5 hash of the file. If the md5 hash is found, it will take the appropriate action, as configured. The file, if malicious and configured correctly, will not be allowed to pass.
2. The firewall does not have a local definition for the file in question, but the cloud has seen the file before.
- The firewall checks the local definitions for the md5 hash and it finds nothing. It then reaches out to the cloud and checks for the md5 hash there. We find a match and the cloud reports back and tells us what its verdict was. The file, if malicious and configured correctly, will not be allowed to pass. This happens within milliseconds and you will see a 'wildfire-upload-skip' in the submission logs.
3. The firewall does not have a local definition for the file in question and neither does the cloud.
- Same as all the other scenarios, but this file has not yet been scanned by the cloud therefore no verdict has been determined. The file will be uploaded to the cloud and the cloud will reply back as soon as it has a verdict on the file. In this scenario, the file will be allowed to pass the first time. Wildfire will not hold the email/file captive in the firewall until a determination has been made. This is not how Wildfire works.
Let me know if I can clarify anything.
Thanks!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!