Palo Alto Networks WildFire service provides protection against unknown threats by analyzing suspicious files and links in a cloud-based or on-premises sandbox environment. This process involves two key phases relevant to the firewall's operation:
Understanding how submissions are triggered and how verdicts are generated and utilized is crucial for leveraging WildFire effectively.
A submission occurs when all the following conditions are met:
This profile (
Objects > Security Profiles > WildFire Analysis
) acts as the filter determining *what gets submitted*:
SSL/TLS Decryption is necessary to identify and submit files transferred within encrypted sessions.
Device > Setup > WildFire > General Settings
).
Once a sample is received by the WildFire cloud or appliance, it undergoes multiple stages of analysis:
Firewalls can also be configured for real-time cloud lookups for unknown hashes, getting verdicts faster than waiting for content updates, provided the sample has been analyzed previously by WildFire from any source.
Monitor > Logs > WildFire Submissions
Monitor > Logs > Threat
For the PCNSE exam, understand:
1. What triggers a file submission to WildFire from a PAN-OS firewall?
2. Which profile type defines *which* file types and applications are eligible for WildFire submission?
3. Which WildFire verdict indicates potentially unwanted software, like adware, but is not necessarily classified as overtly malicious?
4. How does a firewall typically receive protections (signatures) generated by WildFire after analyzing a new threat?
5. What is the most significant limitation preventing WildFire submission for files downloaded over HTTPS?
6. Where are actions based on known WildFire verdicts (e.g., block file if verdict is 'Malware') configured?
7. What is the primary difference between submitting to the WildFire Public Cloud vs. a Private WildFire Appliance?
8. Where would an administrator look to confirm if a specific file was submitted to WildFire and what verdict was returned?
9. What is a key prerequisite for enabling WildFire functionality on a PAN-OS firewall?
10. What does a 'Benign' verdict from WildFire indicate?