Thank you!
Since it’s valid/normal process of Wildfire, what would happen if the NGFW sees the same file (phishing) again? I meant what actions would FW take? is it under Logs-Threat if I need to check its log?
Under Objects- security profile - antivirus profile, there is a profile which I created for antivirus, under Action of the profile there is 'Wildfire Signature Action' tab where i can allow, alert, block…etc for protocols http, pop3, http2…etc, as of now all of them set ‘allow’, what do they mean 'allow' to Wildfire? do I need to set all of them block or drop instead?
Thanks.
... View more