<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EDL - Talos block list in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/190825#M124</link>
    <description>&lt;P&gt;EDL download by firewall only works if the web server which hosts the file allows TLS1.0 connections. The firewall does not support higher TLS versions for EDL downloads.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Dec 2017 13:51:36 GMT</pubDate>
    <dc:creator>Anon1</dc:creator>
    <dc:date>2017-12-08T13:51:36Z</dc:date>
    <item>
      <title>EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/177266#M73</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I have various EDLs setup on various different PA models. Some work, and populate the list with IP's and effectively block in security policies. However,&amp;nbsp; for Cisco Talos block list, it just will not work:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;A href="http://www.talosintelligence.com/feeds/ip-filter.blf" target="_blank"&gt;http://www.talosintelligence.com/feeds/ip-filter.blf&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;It won't populate the list at all when I request to see the list I get:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;vsys1/Cisco Talos IP Black List:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Next update at : Tue Sep 19 02:08:23 2017&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Source : &lt;A href="https://www.talosintelligence.com/feeds/ip-filter.blf" target="_blank"&gt;https://www.talosintelligence.com/feeds/ip-filter.blf&lt;/A&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Referenced : Yes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Valid : Yes&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Auth Valid: Yes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Total invalid entries : 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Valid ips:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;No error&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Service route is set, as other EDLs work fine. All I can think is that this Talos URL resolves to an Amazon AWS address. It still won't work if I tinyurl that AWS address, and add that as the EDL.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 10:24:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/177266#M73</guid>
      <dc:creator>solarstone</dc:creator>
      <dc:date>2017-09-18T10:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/179178#M74</link>
      <description>&lt;P&gt;Had same issue, try changing URL in EDL to &lt;A href="https://talosintelligence.com/documents/ip-blacklist" target="_blank"&gt;https://talosintelligence.com/documents/ip-blacklist&lt;/A&gt; &amp;nbsp; and in CLI run &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;request system external-list refresh type ip name "Cisco Talos IP Black List"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Give it a second, then try&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;request system external-list show type ip name "Cisco Talos IP Black List" &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;post results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 14:43:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/179178#M74</guid>
      <dc:creator>Netwerx</dc:creator>
      <dc:date>2017-09-28T14:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/179197#M75</link>
      <description>&lt;P&gt;Assuming you're running Windows, here's a quick and dirty powershell script I just wrote to download the list for internal hosting. It gets the content, dumps it to CSV file without headers, which I found I had to do otherwise if I just dumped it to a text file, it was one compelte stream of text without any carriage returns, instead of&amp;nbsp;seperate IP addresses. Throw that file on an internally hosted website dedicated for hosting firewall blacklists, and use IP restrictions so only your firewall can pull the data. I also do this for IP addresses I want blocked for longer than the built in max of one hour.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try not to run the script more than once per hour once it's working so they don't temporarilly block you. Change the foldername to the name of the site in IIS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$talos = 'C:\inetpub\wwwroot\&lt;SPAN&gt;NAMEOFINTERNALWEBSITE&lt;/SPAN&gt;\talosTemp.csv'&lt;BR /&gt;Invoke-WebRequest -uri &lt;A href="https://talosintelligence.com/documents/ip-blacklist" target="_blank"&gt;https://talosintelligence.com/documents/ip-blacklist&lt;/A&gt; -OutFile C:\inetpub\wwwroot\&lt;SPAN&gt;NAMEOFINTERNALWEBSITE&lt;/SPAN&gt;\talosTemp.csv&lt;BR /&gt;if((gc $talos | Measure-Object).count -gt 100){&lt;BR /&gt;gc -path $talos | Out-File C:\inetpub\wwwroot\NAMEOFINTERNALWEBSITE\talos.txt -Force -ErrorAction SilentlyContinue -Encoding ascii&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;This is very rudamentary, but it is working for me so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: forgot to add the ascii encoding, feel free to tweak it how you see fit, add more conditional logic as needed, that measure-object is just there to make sure the file isn't empty.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2017 12:39:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/179197#M75</guid>
      <dc:creator>Netwerx</dc:creator>
      <dc:date>2017-09-29T12:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/190677#M123</link>
      <description>&lt;P&gt;You might want to give &lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld" target="_blank"&gt;MineMeld&lt;/A&gt; a try. Either the community version or the AutoFocus hosted one would do the job.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deatails on how to mine this list at &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Talos-Blacklist/td-p/190671/jump-to/first-unread-message" target="_self"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Talos-Blacklist/td-p/190671/jump-to/first-unread-message&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 19:10:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/190677#M123</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-12-07T19:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/190825#M124</link>
      <description>&lt;P&gt;EDL download by firewall only works if the web server which hosts the file allows TLS1.0 connections. The firewall does not support higher TLS versions for EDL downloads.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 13:51:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/190825#M124</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2017-12-08T13:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/305244#M715</link>
      <description>&lt;P&gt;Yes, I do realize this is an older thread but here is what I experienced:&lt;BR /&gt;&lt;BR /&gt;I can open the URL in a browser and see the list of IPs.&amp;nbsp; The firewall does not download the list even though it recognizes the URL.&amp;nbsp; The base URL as published redirects to a much longer URL that changes frequently with updates.&amp;nbsp; That much longer URL is more than the 255 character limit for the URL field.&amp;nbsp; I believe the redirect is where my issue lies.&amp;nbsp; When I try to edit the exclusion list after refreshing the list there are no entries thus I never get a list.&lt;BR /&gt;&lt;BR /&gt;Maybe this can help someone else.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 20:42:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/305244#M715</guid>
      <dc:creator>TNaami</dc:creator>
      <dc:date>2019-12-30T20:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/305909#M721</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Try it with http instead of https.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 23:17:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/305909#M721</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-07T23:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/309978#M754</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;URL : &lt;A href="https://www.talosintelligence.com/feeds/ip-filter.blf" target="_blank"&gt;https://www.talosintelligence.com/feeds/ip-filter.blf&lt;/A&gt; &lt;FONT face="arial,helvetica,sans-serif"&gt;won't populate the list as it is giving 'URL Access error' when i do Test source URL on firewall. Now when i am browsing above url, it is getting redirected to amazon aws link. If we even try to put redirected URL to Test it on firewall, it will not allow as URL is crossing 255 characters, and palo alto can accept at most 255 under url-test node under EDL.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;So this may be the issue here.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;- Mayur&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 09:01:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/309978#M754</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-07T09:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/311443#M759</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73783"&gt;@solarstone&lt;/a&gt;Is it resolved ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 02:54:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/311443#M759</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-17T02:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/523271#M1805</link>
      <description>&lt;P&gt;I have the same problem, I tried the refresh by cli and had this return:&lt;BR /&gt;Details:EDL(vsys1/Dynamic_List_Talos ip) Unable to fetch external dynamic list. No error. Using old copy for refresh.&lt;BR /&gt;EDL(vsys1/Dynamic_List_Talos ip) Manual Refresh job success&lt;/P&gt;
&lt;P&gt;When I test it through the GUI it returns URL access error&lt;/P&gt;
&lt;P&gt;The url I'm using is &lt;A href="https://talosintelligence.com/documents/ip-blacklist" target="_blank"&gt;https://talosintelligence.com/documents/ip-blacklist&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Another point that only a few days ago we started to receive the log in system Unable to fetch external dynamic list. No error. Using old copy for refresh.&lt;/P&gt;
&lt;P&gt;was there any kind of change?&lt;/P&gt;
&lt;P&gt;what was the solution to this problem?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 15:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/523271#M1805</guid>
      <dc:creator>Adriano_R94</dc:creator>
      <dc:date>2022-12-05T15:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: EDL - Talos block list</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/525049#M1818</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209447"&gt;@Adriano_R94&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt; says, I believe that the problem is that the above URL redirects to an AWS URL which is 373 characters long.&amp;nbsp; The maximum size for the EDL Source field is 255, which I think is applied redirects also.&amp;nbsp; To demonstrate, I pasted the AWS URL in the field below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1671914116541.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46408iE74C516D6F67E0D3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1671914116541.png" alt="TomYoung_0-1671914116541.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I solved this problem by fetching the Talos list here -&amp;gt; &lt;A href="http://opendbl.net/" target="_blank" rel="noopener"&gt;http://opendbl.net/&lt;/A&gt;.&amp;nbsp; It has the update date.&amp;nbsp; I did a quick count &lt;EM&gt;now&lt;/EM&gt; on the Talos list, and it had 741 IP addresses just as OpenDBL says.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 24 Dec 2022 20:40:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/edl-talos-block-list/m-p/525049#M1818</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-12-24T20:40:44Z</dc:date>
    </item>
  </channel>
</rss>

