Examining a File Blocking profile

A knowledge base article about Examining a File Blocking profile provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Overview

The Information Security Office (ISO) creates several security profiles that individual departments can use in their own environments. To evaluate these for local use, it is best to review the settings within the management console. In the Palo Alto environment, File Blocking prevents or alerts on file types deemed risky or abnormal from being transferred between systems.

Note: The default profiles used in all campus profile groups do not block files; they are used strictly to log files associated with potential attacks.

How to Access File Blocking Profiles

  1. Log into https://panorama.net.berkeley.edu using single sign-on.
  2. Select the Objects tab from the top navigation bar.
  3. Under the Security Profiles menu in the left pane, select File Blocking.
    Panorama sidebar menu highlighting the File Blocking option under Security Profiles.
  4. Select the profile you wish to examine. For this example, we will look at ucbsec-RD_server (the recommended profile for servers containing Restricted Data).

Understanding File Blocking Rules

Opening the profile displays the rules. Like standard firewall rules, these are processed in order from top to bottom. Items with higher criticality should always be placed at the top of the list.

Rules list for the ucbsec-RD_server profile showing 'Block high risk file types' and 'Block Encrypted File Upload'.

Important Limitations and Forensics

Encryption Limitation: Files will only be detected if the transfer mechanism is not encrypted. If a user is using SSL/TLS, SSH, or another encrypted protocol, the transfer will not be detected or stopped by this profile.

The final rule in the profile is typically used for forensics. it logs the transfer of any recognized file type not already covered by a previous rule, providing an audit trail for investigation.

To exit, click Cancel to return to the main Objects list.


Additional Resources

For technical documentation, visit the vendor site: File Blocking Profile Documentation.