- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-11-2019 06:48 AM
I was wondering ifsomeone could help with clarifying how the WildFire– Proof Point integration works.
A client of ours has Palo Alto NGFW in more geographically distant locations, and they also have Proof Point integrated with Wild Fire.
[1] How and with whom does Proof Point communicate and where is his position in the network?
[2] In regard to the Wild Fire licence, does it have to be on all of the Palo Alto NGFW active in order for Proof Point to work?
[3] Does Proof Point work regardless on which location the licence for WildFire is installed?
Thank you in advance,
05-13-2019 07:37 AM
Hi @Hammer88
There ia no direct integration betqwen something on the firewall and proofpoint. Actually I know only a little about proofpoint email gateway. There you need a wildfire API key. To get such a key you ned at least one active wildfire subscription. For this integration there is no communication between the firewall and proofpoint required as proofpoint uploads the attachments to wildfire. If wildfire sees this as malware a signature is created which the firewall downloada directly from paloalto update servers.
05-13-2019 08:03 AM
Hello,
Here are some replies to your questions:
1. if you setup Proofpoint with the Wildfire API, it would be Proofpoint that sends the request to the wildfire cloud, not your PAN's
2. No. however the PAN's that do not have the license will not get the new signatures as quickly as the ones that do have it. 5-10 minutes with a license, 1+day without license.
3. Yes, Proofpoint sends the requests to the Wildfire cloud via an API. It does not matter where the PAN with the license is located.
Hope that helps.
05-12-2019 03:37 AM
Hi @Hammer88
It depends on the proofpoint product that you have. Actually you need at least one firewall with a wildfire subscription as you need the wildfire API key. But depending on the protection you requires you need a wildfire subscription for more/all your firewalls ... this depends on your current topology and security requirements.
05-13-2019 12:13 AM
Hi @Remo ,
So would you say that the Proof Point , in general, would do the analysis only on the locations where the WildFire licence is active? Can it be done on Firewalls where there is no active WildFire licence?
05-13-2019 07:37 AM
Hi @Hammer88
There ia no direct integration betqwen something on the firewall and proofpoint. Actually I know only a little about proofpoint email gateway. There you need a wildfire API key. To get such a key you ned at least one active wildfire subscription. For this integration there is no communication between the firewall and proofpoint required as proofpoint uploads the attachments to wildfire. If wildfire sees this as malware a signature is created which the firewall downloada directly from paloalto update servers.
05-13-2019 08:03 AM
Hello,
Here are some replies to your questions:
1. if you setup Proofpoint with the Wildfire API, it would be Proofpoint that sends the request to the wildfire cloud, not your PAN's
2. No. however the PAN's that do not have the license will not get the new signatures as quickly as the ones that do have it. 5-10 minutes with a license, 1+day without license.
3. Yes, Proofpoint sends the requests to the Wildfire cloud via an API. It does not matter where the PAN with the license is located.
Hope that helps.
05-19-2019 11:42 PM
Thanks to all very much.
Regards,
02-07-2021 04:02 AM
Dear Team,
I am Looking for Wildfire Initial Configuration for 500 Physical Appliance through cli. Please share if any body have.
Best Regards,
A.yazar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!