<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EDL Performance and Refresh Handling in Panorama in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-performance-and-refresh-handling-in-panorama/m-p/1254462#M6942</link>
    <description>&lt;P&gt;What firewall model are you running?&lt;/P&gt;
&lt;P&gt;Different models can support different amount of IPs from EDLs.&lt;/P&gt;</description>
    <pubDate>Thu, 21 May 2026 13:44:12 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2026-05-21T13:44:12Z</dc:date>
    <item>
      <title>EDL Performance and Refresh Handling in Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-performance-and-refresh-handling-in-panorama/m-p/1254444#M6939</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We are reviewing an EDL-based IOC blocking architecture using Palo Alto Networks firewalls with Panorama and Cortex XDR.&lt;/P&gt;
&lt;P&gt;Currently, IOC blocking is managed mainly with address objects/groups, but we are considering migrating to EDL-only management for operational simplicity and external emergency response through Cortex XDR.&lt;/P&gt;
&lt;P&gt;I would appreciate any field experience or best practices regarding large-scale EDL operations.&lt;/P&gt;
&lt;P&gt;Questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Has anyone operated EDLs at large scale (100K~150K entries)?&lt;BR /&gt;Any noticeable impact on performance, memory, CPU, policy lookup, or refresh processing?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;If a refresh starts before the previous parsing job finishes, how is this internally handled?&lt;BR /&gt;(queueing, overlap prevention, atomic replacement, etc.)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;If an EDL object is created in Panorama Shared context, do EDL content updates require Panorama push/commit to firewalls, or are updates automatically reflected after refresh?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 08:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-performance-and-refresh-handling-in-panorama/m-p/1254444#M6939</guid>
      <dc:creator>.522643</dc:creator>
      <dc:date>2026-05-21T08:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: EDL Performance and Refresh Handling in Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-performance-and-refresh-handling-in-panorama/m-p/1254462#M6942</link>
      <description>&lt;P&gt;What firewall model are you running?&lt;/P&gt;
&lt;P&gt;Different models can support different amount of IPs from EDLs.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 13:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-performance-and-refresh-handling-in-panorama/m-p/1254462#M6942</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2026-05-21T13:44:12Z</dc:date>
    </item>
  </channel>
</rss>

