<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PaloAlto Predefined IP Lists not appearing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579854#M116188</link>
    <description>&lt;P&gt;I am getting "Applications and Threats" updates, but I am not getting "Antivirus" updates (on either the active or passive unit in this HA pair). The default Antivirus Security Profile is present. Both the "Threat Prevention" and "Advanced Threat Prevention" licenses are installed and active. The docs just say that the Threat Prevention license is required:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/built-in-edls" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/built-in-edls&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;With an active Threat Prevention license, Palo Alto Networks provides built-in IP address EDLs that you can use to protect against malicious hosts.&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I can now get to the KB articles which does say in fact say that the AntiVirus dynamic update package is required. I would have guessed it was in the "Applications and Threats" package:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PM0pCAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PM0pCAG&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;H2 class="fieldLabel"&gt;&lt;FONT size="3"&gt;Resolution&lt;/FONT&gt;&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Install Antivirus&amp;nbsp;from GUI:&amp;nbsp;&lt;I&gt;&lt;STRONG&gt;Device &amp;gt; Dynamic Updates&lt;/STRONG&gt;&lt;/I&gt;, before the predefined&amp;nbsp;External Dynamic Lists populate under&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;GUI&lt;STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Objects &amp;gt;&amp;nbsp;External Dynamic Lists&lt;/I&gt;&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;A valid Threat Prevention license is required to be loaded on the Palo Alto Networks Firewall for installing Antivirus.&lt;/LI&gt;
&lt;LI&gt;Applications and Threats needs to be installed on the Firewall before installing Antivirus.&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I just did yet another "Check Now" from the Dynamic Updates page and suddenly the Antivirus packages are showing up and I was able to add the predefined IP lists and the URL list is now populated. I've had this firewall up, licensed, software updated, rebooted for a few weeks (just prepping to insert into live traffic) and never been able to get the AV packages (the entire category never appeared). This firewall has been a problem child since receiving, bought it new from PA with several others and out of the box it was registered to a different company with an expired full trial license package assigned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2024 00:07:47 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2024-03-10T00:07:47Z</dc:date>
    <item>
      <title>PaloAlto Predefined IP Lists not appearing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579833#M116183</link>
      <description>&lt;P&gt;After rechecking licenses, rebooting, checking multiple things, I am unable to get the EDL Predefined IP List dropdown to populate with PA lists (Bulletproof IPs, High risk IPs,. etc.). The Predefined URL List populates with the Authentication Portal Exclusion list, but the list has no entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Threat Prevention license is installed and active&lt;/P&gt;
&lt;P&gt;- Application and Threats dynamic updates are downloading and installing normally&lt;/P&gt;
&lt;P&gt;- "request system external-list show type predefined-ip name &amp;lt;&amp;gt;" does not complete for any name&lt;/P&gt;
&lt;P&gt;- "request system external-list show type predefined-url name &amp;lt;&amp;gt;" completes for panw-auth-portal-exclude-list but the list is not populated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this a wider effect of the KB/Support being down (unable to query license status correctly)? There seem to be a couple KB articles but nothing will load for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2024 00:11:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579833#M116183</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-03-09T00:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto Predefined IP Lists not appearing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579853#M116187</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804"&gt;@Adrian_Jensen&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you confirm that Antivirus package is installed? Build-in EDL objects will appear on the Firewall only when Dynamic Updates like "Applications and Threats" and "Antivirus" are installed on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2024 22:20:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579853#M116187</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-03-09T22:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto Predefined IP Lists not appearing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579854#M116188</link>
      <description>&lt;P&gt;I am getting "Applications and Threats" updates, but I am not getting "Antivirus" updates (on either the active or passive unit in this HA pair). The default Antivirus Security Profile is present. Both the "Threat Prevention" and "Advanced Threat Prevention" licenses are installed and active. The docs just say that the Threat Prevention license is required:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/built-in-edls" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/built-in-edls&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;With an active Threat Prevention license, Palo Alto Networks provides built-in IP address EDLs that you can use to protect against malicious hosts.&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I can now get to the KB articles which does say in fact say that the AntiVirus dynamic update package is required. I would have guessed it was in the "Applications and Threats" package:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PM0pCAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PM0pCAG&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;H2 class="fieldLabel"&gt;&lt;FONT size="3"&gt;Resolution&lt;/FONT&gt;&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Install Antivirus&amp;nbsp;from GUI:&amp;nbsp;&lt;I&gt;&lt;STRONG&gt;Device &amp;gt; Dynamic Updates&lt;/STRONG&gt;&lt;/I&gt;, before the predefined&amp;nbsp;External Dynamic Lists populate under&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;GUI&lt;STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Objects &amp;gt;&amp;nbsp;External Dynamic Lists&lt;/I&gt;&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;A valid Threat Prevention license is required to be loaded on the Palo Alto Networks Firewall for installing Antivirus.&lt;/LI&gt;
&lt;LI&gt;Applications and Threats needs to be installed on the Firewall before installing Antivirus.&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I just did yet another "Check Now" from the Dynamic Updates page and suddenly the Antivirus packages are showing up and I was able to add the predefined IP lists and the URL list is now populated. I've had this firewall up, licensed, software updated, rebooted for a few weeks (just prepping to insert into live traffic) and never been able to get the AV packages (the entire category never appeared). This firewall has been a problem child since receiving, bought it new from PA with several others and out of the box it was registered to a different company with an expired full trial license package assigned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2024 00:07:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579854#M116188</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-03-10T00:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto Predefined IP Lists not appearing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579956#M116200</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea on how to fix up the predefined EDL list names? All my other PaloAltos show the full EDL name as an object. The problem PA is showing the internal/short name as the object in policy rules and I can't seem to change it:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Normal PAs:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-03-11_110202.png" style="width: 763px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58194i07DC261B099CD78D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2024-03-11_110202.png" alt="2024-03-11_110202.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-03-11_110540.png" style="width: 734px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58195iD47B742DF62BEE0A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2024-03-11_110540.png" alt="2024-03-11_110540.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Problem PA:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-03-11_110625.png" style="width: 762px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58196iD29E781FC4289857/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2024-03-11_110625.png" alt="2024-03-11_110625.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-03-11_110838.png" style="width: 656px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58197iDF1A2144BA2CC02C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2024-03-11_110838.png" alt="2024-03-11_110838.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both are running 10.2.7-h3 with current AV and Apps&amp;amp;Threats updates.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 18:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/579956#M116200</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-03-11T18:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto Predefined IP Lists not appearing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/580138#M116217</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804"&gt;@Adrian_Jensen&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for reply and sorry for late response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, I was not able to find a Firewall with this issue in my environment to reproduce it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the screen shot with problematic PA you shared, the EDL name: "panw-torexit-ip-list" is displayed in source, so this makes me think the issue is related to EDL itself rather than how it is displayed in policy. Likely if source is displayed as "Palo Alto Networks - Tor exit IP addresses" instead of "panw-torexit-ip-list" this would resolve it how it is displayed in policy as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I noticed is when I open "Palo Alto Networks - Tor exit IP addresses" from: Objects &amp;gt; External Dynamic List, for approximately one second source is displayed as "panw-torexit-ip-list" before it changes to "Palo Alto Networks - Tor exit IP addresses" (I observed the same for all other built-in EDLs):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1710288458913.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58266i867A0670B4D582CA/image-size/large?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1710288458913.png" alt="PavelK_0-1710288458913.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This makes me think that in case of your problematic PA something is preventing the refresh/update. Could you check Firewall's DNS configuration? Can you see anything in ms.log? Could you try to restart management process?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 00:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/580138#M116217</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-03-13T00:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto Predefined IP Lists not appearing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/580256#M116236</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, panw-torexit-ip-list is the internal configuration name, "&lt;SPAN&gt;Palo Alto Networks - Tor exit IP addresses" is the display name. Sometime between yesterday afternoon and today it seems like the PA suddenly started working and resolving the EDL names correctly (in the EDL configuration and Security Policies). I was running panup-all-antivirus-4753-5271 (3/10 release) at the original problem time. The PA has since downloaded/upgraded the -5272, -5273, and -5274 releases without issue (-5273 last night and -5274 this morning have been installed since I last looked).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have DNS servers setup and it seems to be resolving updates.paloaltonetworks.com/etc. just fine. URL-Cloud is connected and updated. I have multiple FQDN Address Objects setup and the resolve button shows all getting an address, but when I do a "show dns-proxy fqdn all" on the CLI nothing appears except the built-in sinkhole.paloaltonetworks.com object (which doesn't exist anywhere in my config).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 18:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-predefined-ip-lists-not-appearing/m-p/580256#M116236</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-03-13T18:45:08Z</dc:date>
    </item>
  </channel>
</rss>

