| Where Can I Use
This? | What Do I Need? |
Configure Palo Alto Networks firewalls to forward
unknown files or email links and blocked files that match existing
antivirus signatures for analysis. Use the WildFire Analysis profile
to define files to forward to the WildFire private cloud (or additionally,
the public cloud for hybrid could deployments), and then attach
the profile to a security rule to trigger inspection for zero-day
malware.
Specify traffic to be forwarded for analysis based
on the application in use, the file type detected, links contained
in email messages, or the transmission direction of the sample (upload, download,
or both). For example, you can set up the firewall to forward Portable
Executables (PEs) or any files that users attempt to download during
a web-browsing session. In addition to unknown samples, the firewall
forwards blocked files that match existing antivirus signatures.
This provides Palo Alto Networks a valuable source of threat intelligence
based on malware variants that signatures successfully prevented
but neither WildFire nor the firewall has seen before.
You
can extend WildFire analysis resources to a
WildFire Hybrid Cloud, by configuring
the firewall to continue to forward sensitive files to your WildFire
private cloud for local analysis, and forward less sensitive or
unsupported file types to the WildFire public cloud.
Additionally,
you can dedicate WildFire appliance resources to analyze specific
file types: either documents (Microsoft Office files and PDFs) or
PEs. For example, if you deploy a
WildFire Hybrid Cloud to analyze
documents locally and PEs in one of the WildFire public clouds,
you can dedicate all analysis environments to documents. This allows
you to offload analysis of PEs to the public cloud, allowing you
to allocate additional WildFire appliance resources to process sensitive
documents.
Before you begin: