5.8 Ensure that 'Inline Cloud Analysis' on Wildfire profiles is enabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Enable 'Advanced WildFire Inline Cloud Analysis' on Wildfire profiles and forward PE files for analysis. Palo Alto Networks Advanced WildFire operates a series of cloud-based ML detection engines that provide inline analysis of PE (portable executable) files traversing your network to detect and prevent advanced malware in real-time.

Rationale:

Advanced WildFire Inline Cloud Analysis uses a lightweight forwarding mechanism on the firewall to minimize performance impact. The cloud-based ML models are updated seamlessly, to address the ever-changing threat landscape without requiring content updates or feature release support.

Advanced WildFire Inline Cloud Analysis is enabled and configured through the WildFire Analysis profile and requires PAN-OS 11.1 or later with an active Advanced WildFire license.

As of PAN-OS 11.1, only PE file type is supported.

Solution

Navigate to Objects > Security Profiles > Wildfire
On relevant Wildfire profile, checked Enable cloud inline analysis box.
On Inline cloud analysis tab, configure a rule to forward files with the following settings:

Application set to Any

File Type set to PE

Direction set to Both

Action set to Block

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/benchmarks/13792