5.2 Ensure forwarding is enabled for all applications and file types in WildFire file blocking profiles

Information

Set Applications and File Types fields to any in WildFire file blocking profiles. With a WildFire license, seven file types are supported, while only PE (Portable Executable) files are supported without a license.
Rationale:
Selecting 'Any' application and file type ensures WildFire is analyzing as many files as possible.

Solution

Navigate to Objects > Security Profiles > File Blocking.
Set a rule so that Applications is set to any, File Type is set to any, and Action is set to forward.
or
From the CLI:
# set profiles file-blocking "How to configure File Blocking" rules "File Blocking" action forward direction both application any file-type any
Default Value:
Not Configured

See Also

https://workbench.cisecurity.org/files/1780

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4(4), CSCv6|8.5

Plugin: Palo_Alto

Control ID: bbc6a4a4d6d4a4a753aff531ea52b9cf50212fa37984296c3745bc421cdce9ac