<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Questions about EDL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556270#M112941</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/238781"&gt;@Charlie80&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does not necessary mean that paloalto consider it as benign, but maybe it is simply not confident enough to add it as the goal also is to have as few as possible false positives. 28% confidence on abjseIP is also not that high. In addition you will always find other sources with additional IP/URLs that are not blocked by paloalto as this company also does not know everything. Sometimes it makes sense to create such drop policies with more than just one list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;isn't it updated with the antivirus updates as only this one is updated daily?&lt;/P&gt;</description>
    <pubDate>Sun, 03 Sep 2023 06:32:49 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2023-09-03T06:32:49Z</dc:date>
    <item>
      <title>Questions about EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556112#M112920</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a firewall rule on the Internet Firewall list this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source: Palo Alto Networks - High risk IP addresses - Palo Alto Networks - Known malicious IP addresses&lt;/P&gt;
&lt;P&gt;Destination Any&lt;/P&gt;
&lt;P&gt;Service Any&lt;/P&gt;
&lt;P&gt;Action: drop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if an ip inside the two EDL try to reach a Public Customer Service will be drop right?&lt;/P&gt;
&lt;P&gt;How is this list updated? There is a package like the Threat that I have to download with the PA scheduler?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found an ip that is flagged&amp;nbsp; as &lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;malicious&lt;/SPAN&gt;&lt;/SPAN&gt; by AbuseIPDB with the 28% of confidence.&lt;/P&gt;
&lt;P&gt;I check the same ip on the Internet firewall:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;request system external-list global-find string x.x.x.x&lt;/P&gt;
&lt;P&gt;the answer was IP not present in the list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So It's means that Palo Alto didn't consider this ip malicious?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 08:52:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556112#M112920</guid>
      <dc:creator>Charlie80</dc:creator>
      <dc:date>2023-09-01T08:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556117#M112923</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/238781"&gt;@Charlie80&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, an IP within the EDL should be dropped by your policy.&lt;/P&gt;
&lt;P&gt;With an active &lt;STRONG&gt;Threat Prevention license&lt;/STRONG&gt;, Palo Alto Networks provides multiple built-in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="xref"&gt;&lt;A style="color: #fa582d;" href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/built-in-edls.html" target="external_window"&gt;dynamic IP lists that you can use to block malicious hosts&lt;/A&gt;&lt;/SPAN&gt;. The list is updated daily.&amp;nbsp; The download is part of the Threats dynamic update schedule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 10:42:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556117#M112923</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-09-01T10:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556123#M112928</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Have you any idea regarding the last question?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found an ip that is flagged&amp;nbsp; as &lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;malicious&lt;/SPAN&gt;&lt;/SPAN&gt; by AbuseIPDB with the 28% of confidence.&lt;/P&gt;
&lt;P&gt;I check the same ip on the Internet firewall:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;request system external-list global-find string x.x.x.x&lt;/P&gt;
&lt;P&gt;the answer was IP not present in the list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So It's means that Palo Alto didn't consider this ip malicious?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 11:46:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556123#M112928</guid>
      <dc:creator>Charlie80</dc:creator>
      <dc:date>2023-09-01T11:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556270#M112941</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/238781"&gt;@Charlie80&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does not necessary mean that paloalto consider it as benign, but maybe it is simply not confident enough to add it as the goal also is to have as few as possible false positives. 28% confidence on abjseIP is also not that high. In addition you will always find other sources with additional IP/URLs that are not blocked by paloalto as this company also does not know everything. Sometimes it makes sense to create such drop policies with more than just one list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;isn't it updated with the antivirus updates as only this one is updated daily?&lt;/P&gt;</description>
      <pubDate>Sun, 03 Sep 2023 06:32:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/556270#M112941</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2023-09-03T06:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/579027#M116094</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Team,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We are not able to add Predefine EDL list into the security Policy. Please help on it.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 14:50:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/579027#M116094</guid>
      <dc:creator>ltinetwork</dc:creator>
      <dc:date>2024-03-01T14:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/579035#M116095</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1468775903"&gt;@ltinetwork&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What seems to be the problem ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;With an active Threat Prevention license&lt;/STRONG&gt;&lt;/EM&gt;, Palo Alto Networks provides built-in IP address EDLs that you can use to protect against malicious hosts.&amp;nbsp; You should be able to select&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;them as a s&lt;/SPAN&gt;ource or destination address object in a Security Policy Rule as shown below.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1709306974471.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58013iBA02407CFC6ABD11/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1709306974471.png" alt="kiwi_0-1709306974471.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What seems to be the problem exactly ?&lt;/P&gt;
&lt;P&gt;You don't see them ? Is your threat license active ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 15:31:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-about-edl/m-p/579035#M116095</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-03-01T15:31:57Z</dc:date>
    </item>
  </channel>
</rss>

