Set Up Antivirus, Anti-Spyware, and Vulnerability Protection (NGFW (Managed by PAN-OS or Panorama))
Focus
Focus
Advanced Threat Prevention Powered by Precision AI™

Set Up Antivirus, Anti-Spyware, and Vulnerability Protection (NGFW (Managed by PAN-OS or Panorama))

Table of Contents


Set Up Antivirus, Anti-Spyware, and Vulnerability Protection (NGFW (Managed by PAN-OS or Panorama))

Palo Alto Networks defines a default action for all anti-spyware and vulnerability protection signatures. To see the default action, select ObjectsSecurity ProfilesAnti-Spyware or ObjectsSecurity ProfilesVulnerability Protection and then select a profile. Click the Exceptions tab and then click Show all signatures to view the list of the signatures and the corresponding default Action. To change the default action, create a new profile and specify an Action, and/or add individual signature exceptions to Exceptions in the profile.
  1. Verify that you have a Threat Prevention subscription.
    The Threat Prevention subscription bundles the antivirus, anti-spyware, and vulnerability protection features in one license. To verify that you have an active Threat Prevention subscription, select DeviceLicenses and verify that the Threat Prevention expiration date is in the future.
  2. Download the latest content.
    1. Select DeviceDynamic Updates and click Check Now at the bottom of the page to retrieve the latest signatures.
    2. In the Actions column, click Download and install the latest Antivirus updates and then download and then Install the latest Applications and Threats updates.
  3. Schedule content updates.
    Review the Best Practices for Applications and Threats Content Updates for important information on deploying updates.
    1. Select DeviceDynamic Updates and then click Schedule to automatically retrieve signature updates for Antivirus and Applications and Threats.
    2. Specify the frequency and timing for the updates:
      • download-only—The firewall automatically downloads the latest updates per the schedule you define but you must manually Install them.
      • download-and-install—The firewall automatically downloads and installs the updates per the schedule you define.
    3. Click OK to save the update schedule; a commit is not required.
    4. (Optional) Define a Threshold to indicate the minimum number of hours after an update becomes available before the firewall will download it. For example, setting the Threshold to 10 means the firewall will not download an update until it is at least 10 hours old regardless of the schedule.
    5. (HA only) Decide whether to Sync To Peer, which enables peers to synchronize content updates after download and install (the update schedule does not sync across peers; you must manually configure the schedule on both peers).
      There are additional considerations for deciding if and how to Sync To Peer depending on your HA deployment:
      • Active/Passive HA—If the firewalls are using the MGT port for content updates, then schedule both firewalls to download and install updates independently. However, if the firewalls are using a data port for content updates, then the passive firewall will not download or install updates unless and until it becomes active. To keep the schedules in sync on both firewalls when using a data port for updates, schedule updates on both firewalls and then enable Sync To Peer so that whichever firewall is active downloads and installs the updates and also pushes the updates to the passive firewall.
      • Active/Active HA—If the firewalls are using the MGT interface for content updates, then select download-and-install on both firewalls but do not enable Sync To Peer. However, if the firewalls are using a data port, then select download-and-install on both firewalls and enable Sync To Peer so that if one firewall goes into the active-secondary state, the active-primary firewall will download and install the updates and push them to the active-secondary firewall.
  4. (Optional) Create custom security profiles for antivirus, anti-spyware, and vulnerability protection.
    Alternatively, you can use the predefined default or strict profiles.
    Transition safely to best practice Security profiles for the best security posture.
  5. Attach security profiles to your Security policy rules.
    When you configure the firewall with a Security policy rule that uses a Vulnerability Protection profile to block connections, the firewall automatically blocks that traffic in hardware (see Monitor Blocked IP Addresses).
    1. Select PoliciesSecurity and select the rule you want to modify.
    2. In the Actions tab, select Profiles as the Profile Type.
    3. Select the security profiles you created for Antivirus, Anti-Spyware, and Vulnerability Protection.
  6. Commit your changes.
    Click Commit.