CNGFW for Azure offers two levels of protection: Standard WildFire and
Advanced WildFire (Precision AI-powered inline blocking). Use the
steps below to configure either profile type:
Create the profile.
Log in to Panorama and navigate to Objects > WildFire
Analysis.
Select the correct Device Group from the drop-down.
Click Add and enter a unique Name for the
profile.
Configure Inline Analysis (Applicable for enabling Advanced WildFire
Profile).
If you are licensed for Advanced WildFire and wish to
block zero-day malware in real-time:
Go to the Inline Cloud Analysis tab.
Select the Enable Cloud Inline Analysis checkbox.
Enabling this service will appear as a separate add-on in your CNGFW
for Azure billing metrics at 30% of the base firewall credit
cost.
Define Analysis Rules.
Click Add within the profile window to create specific rules.
Name: Enter a descriptive name for the rule.
Applications: Click Add to select
specific applications (or "any") to monitor.
File Types: Select the specific file formats you
wish to analyze.
Direction: Choose upload,
download, or both.
Analysis Destination:
Public Cloud: Forwards traffic to the WildFire
public cloud.
Private Cloud: Forwards traffic to a local
WildFire appliance.
Finalize and deploy.
Click OK to save the profile.
Commit the changes to Panorama.
Push the configuration to your managed
devices.
Define Security Rules
Log in to Panorama, and click policy rules.
Choose the required Device Group and click the preconfigured security rule
(pre-rule or post-rule) or create a new rule.
Click Actions.
In the profile setting, select Profiles under the
profile type.
Select the WildFire profile you wish to choose in the WildFire
Analysis drop-down.
Click OK.
Commit and push the device group to the Cloud NGFW resources.
After you create the Log Analytics Workspace, update the log settings under the
firewall and start sending the traffic. Once the traffic is sent, you can view
the logs as described in the steps below:
Click the Log Analytics Workspace for which you need
to view the logs.
Click Logs.
Click Custom Logs in the query window and
Run a query you have created.
You can create a customized query with parameters such as number of
logs, time range and so on. For example - A simple Query
fluentbit_CL
| limit 10
Click the desired query result item for which you would want to view the
detailed logs.
View Logs in Panorama
On Panorama, you can view the logs on the device group using Monitor >
Threats.