A knowledge base article about How to customize a security profile provided by the UC Berkeley IT Service Hub - Knowledge Portal
Overview
For many campus firewall administrators, the Panorama “Security Profiles” created by the Information Security Office (ISO) represent an acceptable balance between security and functionality and work in most cases. These shared profiles can be identified by names starting with ucbsec- and are located in the “Global” Device group. However, there may be cases where a profile needs to be customized to meet a specific departmental use case.
Note on Encryption: Without SSL/TLS decryption, File Blocking profiles only apply to files downloaded without that encryption. Many legitimate sites use SSL/TLS, so the current File Blocking profile will not interfere with downloads from those secured sites.
Customization Example: Unblocking 7-Zip Files
The following steps demonstrate how to customize a File Blocking profile to allow the downloading of .7z files.
- Log into https://panorama.net.berkeley.edu using single sign-on.
- From the tabs at the top of the window, choose Objects.
- Under Security Profiles in the left pane, choose File Blocking.

- From the list of File Blocking profiles, select the one that most closely matches your needs (in this example,
ucbsec-user).

- Click the Clone button.
- When the Clone dialog box appears, click OK. Ensure the Destination for the clone is the vsys you are managing (in this example, the vsys is named
ISO_Test1).

- The profile will be cloned to your departmental vsys and named
ucbsec-user-1.
- Find the
ucbsec-user-1 profile and click on it to open the File Blocking Profile window.
- Rename the profile to something descriptive that will not be confused with shared profiles (e.g.,
ISO_Test1 File Block).
- To remove 7-Zip from the block list, click the box next to 7z (the 7-Zip file extension) and select Delete.

- Click OK.
- From the Commit menu near the top of the screen, choose Commit to Panorama. When finished, select Push to Device from the same menu.

Best Practices for Deployment
At this point, the new profile is available to add to your firewall rules.
- Individual Hosts: If the custom profile is only for a single host, add it (along with AntiVirus, Vulnerability Protection, etc.) via the Actions tab of the specific rule using the Profile Type Profiles.
- Multiple Devices: If this selection of profiles will be used across multiple devices, it is recommended to create a Profile Group. Applying a Profile Group ensures that all security settings remain consistent across all associated firewall rules with a single selection.