Install WildFire Content Updates from an SCP-Enabled Server

Where Can I Use This?
What Do I Need?
  • WildFire Appliance
  • WildFire License
The following procedure describes how to install threat intelligence content updates on a WildFire appliance that does not have direct connectivity to the Palo Alto Networks Update Server. You will need a Secure Copy (SCP)-enabled server to temporarily store the content update.
  1. Retrieve the content update file from the update server.
    1. Log in to the Palo Alto Networks Support Portal and click
      Dynamic Updates
    2. In the WildFire Appliance section, locate the latest WildFire appliance content update and download it.
    3. Copy the content update file to an SCP-enabled server and note the file name and directory path.
  2. Install the content update on the WildFire appliance.
    1. Log in to the WildFire appliance and download the content update file from the SCP server:
      scp import wf-content from username@host:path
      For example:
      scp import wf-content from bart@
      If your SCP server is running on a non-standard port or if you need to specify the source IP, you can also define those options in the
      scp import
    2. Install the update:
      request wf-content upgrade install file panup-all-wfmeta-2-253.tgz
    3. View the status of the installation:
      show jobs all
  3. Verify the content update.
    Verify the content version:
    show system info | match wf-content-version
    The following output now shows version 2-253:
    wf-content-version: 2-253

Recommended For You