A knowledge base article about Update Schedules for bSecure (Palo Alto) Security Features and Shared Objects provided by the UC Berkeley IT Service Hub - Knowledge Portal
The Palo Alto firewall platform includes various security features and shared objects that must be updated periodically. These include security definitions (such as virus and vulnerability signatures) and shared objects (such as malicious IP address feeds). Below are the update frequencies used in the campus environment.
Refer to individual feature documentation for detailed information on these protections.
| Feature | Update Schedule |
|---|---|
| AntiVirus | Hourly * |
| Applications and Threats | Every 30 minutes * |
| WildFire | Every minute |
* Implementation Delay: For AntiVirus and Applications and Threats, there is a mandatory 8-hour delay in the implementation of new signatures. This safety window allows for global issues to be detected and corrected by the vendor prior to campus-wide deployment.
For more information on these objects, see: KB0012858 - bSecure Shared Objects & Threat Intelligence.
| Shared Object | Update Schedule |
|---|---|
ucbsec-vuln_scanners |
Manual update as needed |
ucbsec-URLs |
Manual update as needed |
UCB-networks_no_visitor |
Daily at 01:00 |
UCB-airbears2 |
Daily at 01:00 |
UCB-calvisitor |
Daily at 01:00 |
UCB-VPN |
Manual update as needed |
ucbsec-tor_exit_nodes |
Hourly |
threat-AID_list |
Hourly |
threat-malicious_IPv4 |
Hourly |
threat-malicious_IPv6 |
Hourly |
threat-malicious_FQDN |
Hourly |
threat-malicious_URLs |
Hourly |
| Palo Alto Networks - High risk IP addresses | Hourly |
| Palo Alto Networks - Known malicious IP addresses | Hourly |