For each type of traffic that you want to
inspect for viruses, select an action from the drop-down. You can
define different actions for standard antivirus signatures (Signature Action column),
signatures generated by the WildFire system (WildFire
Signature Action column), and malicious threats detected
in real-time by the WildFire Inline ML models (WildFire
Inline ML Action column). Some environments may
have requirements for a longer soak time for antivirus signatures,
so this option enables the ability to set different actions for
the two antivirus signature types provided by Palo Alto Networks.
For example, the standard antivirus signatures go through a longer
soak period before being released (24 hours), versus WildFire signatures,
which can be generated and released within 15 minutes after a threat
is detected. Because of this, you may want to choose the alert action
on WildFire signatures instead of blocking.
For
the best security, clone the default Antivirus profile and set the
Action and WildFire Action for all the decoders to reset-both and
attach the profile to all Security policy rules that allow traffic.
|