5.8 Ensure that 'Inline Cloud Analysis' on Wildfire profiles is enabled

Information

Enable 'Advanced WildFire Inline Cloud Analysis' on Wildfire profiles and forward PE files for analysis. Palo Alto Networks Advanced WildFire operates a series of cloud-based ML detection engines that provide inline analysis of PE (portable executable) files traversing your network to detect and prevent advanced malware in real-time.

Rationale:

Advanced WildFire Inline Cloud Analysis uses a lightweight forwarding mechanism on the firewall to minimize performance impact. The cloud-based ML models are updated seamlessly, to address the ever-changing threat landscape without requiring content updates or feature release support.

Advanced WildFire Inline Cloud Analysis is enabled and configured through the WildFire Analysis profile and requires PAN-OS 11.1 or later with an active Advanced WildFire license.

As of PAN-OS 11.1, only PE file type is supported.

Solution

Navigate to Objects > Security Profiles > Wildfire
On relevant Wildfire profile, checked Enable cloud inline analysis box.
On Inline cloud analysis tab, configure a rule to forward files with the following settings:

Application set to Any

File Type set to PE

Direction set to Both

Action set to Block

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/benchmarks/17915

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.3

Plugin: Palo_Alto

Control ID: cc37377b1d4107f473549dca1cd395e9c07edd0b3e97cb12c3b910fe301e4699