6.20 Ensure that 'Wildfire Inline ML Action' on antivirus profiles are set to reset-both on all decoders except 'imap' and 'pop3'

Information

Configure 'Wildfire Inline ML Action' on antivirus profiles to a value of 'reset-both' for all decoders except imap and pop3 under 'Wildfire Inline ML Action'. If required by the organization's email implementation, configure imap and pop3 decoders to 'alert' under 'Wildfire Inline ML Action'.

Rationale:

Starting from PanOS 10, Wildfire supports real-time detection and blocking. As more attacks are designed to bypass signature-based protection, real-time signatureless-based protection is needed. Antivirus signatures produce low false positives. By blocking any detected malware through the specified decoders, the threat of malware propagation through the firewall is greatly reduced. It is recommended to mitigate malware found in pop3 and imap through a dedicated antivirus gateway. Due to the nature of the pop3 and imap protocols, the firewall is not able to block only a single email message containing malware. Instead, the entire session would be terminated, potentially affecting benign email messages.

Solution

Navigate to Objects > Security Profiles > Antivirus
Set antivirus profiles to have all decoders set to reset-both for Wildfire Inline ML Action. If imap and pop3 are required in the organization, set the imap and pop3 decoders are set to alert for Wildfire Inline ML Action.

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/benchmarks/13792

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.3

Plugin: Palo_Alto

Control ID: e3764a3be770d49b24c2610a13833e4b3a87823e05be862d1aadf9ec73ba1399