<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Combining IP and URL EDL on Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1240261#M125380</link>
    <description>&lt;P&gt;Thanks for that! &amp;nbsp;Is it preferable to also add the respective Palo applications to the rules as well (i.e. OneDrive, Microsoft-base, etc) to restrict it down or keep it more open by leaving it as application-default?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 18 Oct 2025 00:43:38 GMT</pubDate>
    <dc:creator>roryschmitz</dc:creator>
    <dc:date>2025-10-18T00:43:38Z</dc:date>
    <item>
      <title>Combining IP and URL EDL on Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1240256#M125378</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're adding the Microsoft 365 EDLs from here:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service" target="_blank"&gt;EDL Hosting Service.&lt;/A&gt;&amp;nbsp;&amp;nbsp;The goal is to allow access to all M365 IPs and URLs outbound.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's best practice if I have two separate EDLs, one for IPs and one for URLs?&amp;nbsp;&amp;nbsp;I see that IP-based EDLs can be used in the Destination portion of the rule, and URLs appear to be only selectable in the Service/URL Category.&amp;nbsp;&amp;nbsp;Can we combine these onto one rule or would we require multiple?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice would be appreciated.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 20:02:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1240256#M125378</guid>
      <dc:creator>roryschmitz</dc:creator>
      <dc:date>2025-10-17T20:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Combining IP and URL EDL on Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1240258#M125379</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257832"&gt;@roryschmitz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Great question! Just a heads up, If you were to combine an IP EDL in the destination and a URL EDL in the URL category of a single rule, the traffic would need to match both&amp;nbsp;the destination IP address from the IP EDL *AND* the URL from the URL EDL for that rule to be applied.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your scenario, the best practice would be to create 2 separate Security Policies that reference the IP EDL and the URL/Domain.&amp;nbsp; EDL.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 22:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1240258#M125379</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-10-17T22:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Combining IP and URL EDL on Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1240261#M125380</link>
      <description>&lt;P&gt;Thanks for that! &amp;nbsp;Is it preferable to also add the respective Palo applications to the rules as well (i.e. OneDrive, Microsoft-base, etc) to restrict it down or keep it more open by leaving it as application-default?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Oct 2025 00:43:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1240261#M125380</guid>
      <dc:creator>roryschmitz</dc:creator>
      <dc:date>2025-10-18T00:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Combining IP and URL EDL on Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1243169#M125648</link>
      <description>&lt;P&gt;Don't use "application-default" in a block rule. In a block rule, if you specify "application-default", then any traffic that is on off-ports will not be blocked. For this reason, the ports in the block rule must be set to "any" if your intent is to block all traffic. "application-default" is really meant for allow rules.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 14:07:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1243169#M125648</guid>
      <dc:creator>runyons</dc:creator>
      <dc:date>2025-12-04T14:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Combining IP and URL EDL on Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1243362#M125660</link>
      <description>&lt;P&gt;Thank you for the clarification on application-defaults and the rule types.&amp;nbsp; Much appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 15:39:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/combining-ip-and-url-edl-on-rules/m-p/1243362#M125660</guid>
      <dc:creator>roryschmitz</dc:creator>
      <dc:date>2025-12-08T15:39:45Z</dc:date>
    </item>
  </channel>
</rss>

