<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External Dynamic List is not showing while creating a policy. in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1226203#M5789</link>
    <description>&lt;P&gt;The EDL first needs to be populated/work before it can be used in a security rule.&lt;/P&gt;
&lt;P&gt;if you just created the EDL and it is not showing up, make sure the 'Test Source URL' doesn't give you an error. if this works and it's still not showing up as an option, try committing the config first and revisit the EDL after the commit completes to see if there are entries in the 'List Entries and Exceptions' tab. Once the tab is populated, you should be able to add the EDL to a security rule&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;pitfalls:&lt;/P&gt;
&lt;P&gt;- does the EDL require authentication?&lt;/P&gt;
&lt;P&gt;- is your management interface allowed to connect to the source URL (check security rules, use a service route if needed)&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2025 10:57:04 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2025-04-10T10:57:04Z</dc:date>
    <item>
      <title>External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/615744#M4922</link>
      <description>&lt;P&gt;I am trying to create an external dynamic list to block incoming traffic from some IPs. I have created an EDL list listening to a server on LAN to fetch the IPs. However when I am trying to create a policy the EDL option is not showing under the drop down menu. Is there any thing I am missing?&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Screenshots are attached for reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63698i594EA59AFBA6A511/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63697i96ECF18917F77087/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63699i02859E4685014C65/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;   &lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 07:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/615744#M4922</guid>
      <dc:creator>N.inMedicalSciences</dc:creator>
      <dc:date>2024-10-30T07:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/615764#M4924</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1222649905"&gt;@N.inMedicalSciences&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you type in the first few letters of the EDL name to show that their are no matches in the drop down list?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 12:48:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/615764#M4924</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-10-30T12:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/996194#M5126</link>
      <description>&lt;P&gt;Clicking &lt;STRONG&gt;Test Source URL&lt;/STRONG&gt; button gives URL access error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 634px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64443iBFC202DA74AF7187/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, the link is accessible when checking on browser:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image2.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64444i00594EE5EE6A7504/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image2.png" alt="image2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 11:59:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/996194#M5126</guid>
      <dc:creator>N.inMedicalSciences</dc:creator>
      <dc:date>2024-12-03T11:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/996203#M5129</link>
      <description>&lt;P&gt;this means the management interface does not have access to the URL, you may be blocking it on the firewall or on an access list on the server?&lt;/P&gt;
&lt;P&gt;Verify your traffic logs to see if it is maybe hitting a drop rule (make sure you account for the implied drop rule, it may be getting discarded without log)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the EDL will not show up in the policy until it is populated with _something_ (else you would be building an invalid policy) so you need to create the EDL and have the firewall fetch the entries before using it in a rule&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 12:19:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/996203#M5129</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-12-03T12:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/996399#M5140</link>
      <description>&lt;P&gt;Using the command&amp;nbsp;&lt;STRONG&gt;show interface management,&amp;nbsp;&lt;/STRONG&gt;got Management IP address as 172.16.39.9. Then logged in as admin and was able to ping the server hosting EDL, which is running on 172.16.36.8.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ping.png" style="width: 565px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64459i1B7AF29320EDD5EA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ping.png" alt="ping.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checked the traffic logs but saw no deny for 172.16.39.9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate the help getting by the community.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 05:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/996399#M5140</guid>
      <dc:creator>N.inMedicalSciences</dc:creator>
      <dc:date>2024-12-04T05:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/996445#M5146</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1222649905"&gt;@N.inMedicalSciences&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your 1st issue was the EDL did not show up in the drop down.&amp;nbsp; I saw that you had a lot of entries.&amp;nbsp; The NGFW will only show a limited number of items in the drop down.&amp;nbsp; I asked you to start typing in the name of the EDL so it would show up.&amp;nbsp; I got no response from you.&amp;nbsp; The EDL &lt;EM&gt;will&lt;/EM&gt; show up in the drop down after you create it.&amp;nbsp; The EDL does not need to be populated before it will show up in a policy.&amp;nbsp; I have configured it many times.&amp;nbsp; There are some caveats on Panorama, but you are not using Panorama.&amp;nbsp; In fact, the NGFW will NOT automatically retrieve the EDL &lt;EM&gt;until&lt;/EM&gt; it is used in a policy.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/external-dynamic-lists/view-external-dynamic-list-entries" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/external-dynamic-lists/view-external-dynamic-list-entries&lt;/A&gt; ("The list might be empty if:").&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your 2nd issue is your URL access error.&amp;nbsp; Unless you have a bug, the issue is that the management interface cannot open the URL as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; said.&amp;nbsp; I am curious why you blacked out the URL from your browser image.&amp;nbsp; It may be just habit.&amp;nbsp; It should be 172.16.36.8, just like you said and is, in fact, clearly shown in your 1st image.&amp;nbsp; The browser URL and EDL URL need to match exactly as a good test.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a known bug with 9.1 &lt;EM&gt;when using client authentication&lt;/EM&gt;.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MUqCAM&amp;amp;lang=en_US" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MUqCAM&amp;amp;lang=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are not using client authentication.&amp;nbsp; (I also saw the bug listed for 10.1.5, which was weird.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a good document to troubleshoot further.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001Vx5CAE&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001Vx5CAE&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 09:47:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/996445#M5146</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-12-04T09:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1225855#M5773</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm dealing with the same issue, have you manage to found a solution for that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 17:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1225855#M5773</guid>
      <dc:creator>A.Asimakopoulos</dc:creator>
      <dc:date>2025-04-07T17:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1225953#M5775</link>
      <description>&lt;P&gt;Have you tried checking the service route configuration and verified that it's using the management interface for all?&amp;nbsp; If not, you can check to see what interface EDL is configured for&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="securehops_1-1744126593980.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67020i8BC5C802FE831EE5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="securehops_1-1744126593980.png" alt="securehops_1-1744126593980.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 15:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1225953#M5775</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2025-04-08T15:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1226062#M5781</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your reply, management interface is used for all services. However, i manage to find a solution for my issue, the custom EDL had authentication and the credentials was cached on my browser, when i tried to visit the internal EDL from a private browser, it prompted to provide credentials. This is why it giving the error, once the web server was accessible without authentication it worked like a charm.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 09:25:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1226062#M5781</guid>
      <dc:creator>A.Asimakopoulos</dc:creator>
      <dc:date>2025-04-09T09:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic List is not showing while creating a policy.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1226203#M5789</link>
      <description>&lt;P&gt;The EDL first needs to be populated/work before it can be used in a security rule.&lt;/P&gt;
&lt;P&gt;if you just created the EDL and it is not showing up, make sure the 'Test Source URL' doesn't give you an error. if this works and it's still not showing up as an option, try committing the config first and revisit the EDL after the commit completes to see if there are entries in the 'List Entries and Exceptions' tab. Once the tab is populated, you should be able to add the EDL to a security rule&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;pitfalls:&lt;/P&gt;
&lt;P&gt;- does the EDL require authentication?&lt;/P&gt;
&lt;P&gt;- is your management interface allowed to connect to the source URL (check security rules, use a service route if needed)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 10:57:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/external-dynamic-list-is-not-showing-while-creating-a-policy/m-p/1226203#M5789</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-04-10T10:57:04Z</dc:date>
    </item>
  </channel>
</rss>

