Inline Cloud Analysis for Advanced WildFire provides real-time advanced malware
protection by leveraging the analysis capabilities of the Advanced WildFire Cloud.
| Where Can I Use This? | What Do I Need? |
Palo Alto Networks Advanced WildFire operates a series of cloud-based ML
detection engines that provide inline analysis of PE (portable executable) files
traversing your network to detect and prevent advanced malware in real-time. As with
other malicious content that WildFire detects, threats detected by Advanced WildFire
Inline Cloud Analysis generate a signature that is then disseminated to customers
through an update package, providing a future defense for all Palo Alto Networks
customers.
The cloud-based engines enable the detection of never-before-seen malware
(e.g., a Palo Alto Networks zero-day - malware previously unseen in the wild or by
Palo Alto Networks) and block it from entering your environment. Advanced WildFire
Inline Cloud Analysis uses a lightweight forwarding mechanism on the firewall to
minimize performance impact. The cloud-based ML models are updated seamlessly, to
address the ever-changing threat landscape without requiring content updates or
feature release support.
Because this feature functions by performing real-time queries against the Advanced
WildFire cloud service, it requires a persistent, active cloud connection to analyze
and mitigate threats effectively. Without a continuous connection to the cloud
service, the system cannot perform the live lookups necessary to identify and
prevent advanced malware in real-time.
When the Advanced WildFire license is enabled, the firewall performs PAN-DB URL
categorization lookups as part of its internal processing, independent of any
URL Filtering license or explicit cloud inline configuration. This is
facilitated by the Cloud Content FQDN, which is enabled by default to connect to
hawkeye.services-edge.paloaltonetworks.com and then resolve to the closest cloud
services server. This is configured from:
If you experience service connectivity issues, verify that the configured
cloud content FQDN is not being blocked.
Advanced WildFire Inline Cloud Analysis is enabled and configured through
the WildFire Analysis profile and requires PAN-OS 11.1 or later with an active
Advanced WildFire license.