1. Home
  2. Security Hardening
  3. CIS Palo Alto Firewall 6 Benchmark L1 V1.0.0
  4. Ensure forwarding is enabled for all applications and file types in WildFire file blocking profiles

Ensure forwarding is enabled for all applications and file types in WildFire file blocking profiles

Details

Set Applications and File Types fields to any in WildFire file blocking profiles. With a WildFire license, seven file types are supported, while only PE (Portable Executable) files are supported without a license.

Rationale:

Selecting ‘Any’ application and file type ensures WildFire is analyzing as many files as possible.

Solution

Navigate to Objects > Security Profiles > File Blocking.
Set a rule so that Applications is set to any, File Type is set to any, and Action is set to forward.
or
From the CLI:
# set profiles file-blocking “How to configure File Blocking” rules “File Blocking” action forward direction both application any file-type any
Default Value:
Not Configured

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Information Integrity.This control applies to the following type of system Palo_Alto.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles