A knowledge base article about Examining a File Blocking profile provided by the UC Berkeley IT Service Hub - Knowledge Portal
Table of Contents
The Information Security Office (ISO) creates several security profiles that individual departments can use in their own environments. To evaluate these for local use, it is best to review the settings within the management console. In the Palo Alto environment, File Blocking prevents or alerts on file types deemed risky or abnormal from being transferred between systems.
Note: The default profiles used in all campus profile groups do not block files; they are used strictly to log files associated with potential attacks.
ucbsec-RD_server (the recommended profile for servers containing Restricted Data).Opening the profile displays the rules. Like standard firewall rules, these are processed in order from top to bottom. Items with higher criticality should always be placed at the top of the list.
Encryption Limitation: Files will only be detected if the transfer mechanism is not encrypted. If a user is using SSL/TLS, SSH, or another encrypted protocol, the transfer will not be detected or stopped by this profile.
The final rule in the profile is typically used for forensics. it logs the transfer of any recognized file type not already covered by a previous rule, providing an audit trail for investigation.
To exit, click Cancel to return to the main Objects list.
For technical documentation, visit the vendor site: File Blocking Profile Documentation.