5.2 Ensure forwarding is enabled for all applications and file types in WildFire file blocking profiles

Information

Set Applications and File Types fields to any in WildFire file blocking profiles. With a WildFire license, seven file types are supported, while only PE (Portable Executable) files are supported without a license.
Rationale:
Selecting 'Any' application and file type ensures WildFire is analyzing as many files as possible.

Solution

Navigate to Objects > Security Profiles > File Blocking.
Set a rule so that Applications is set to any, File Type is set to any, and Action is set to forward.
or
From the CLI:
# set profiles file-blocking "How to configure File Blocking" rules "File Blocking" action forward direction both application any file-type any
Default Value:
Not Configured

See Also

https://workbench.cisecurity.org/files/1780

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4(4), CSCv6|8.5

Plugin: Palo_Alto

Control ID: b387f26f0324ab6862db46dd0467247f3b7e610ba666865b2703e1dab9d5cc7c