<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Github EDLs missing IPs? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265600#M127110</link>
    <description>&lt;DIV style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"&gt;
&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we've been using the Palo Alto managed GitHub EDL to allow access to GitHub and recently noticed some connections being blocked because the destination IPs aren't covered by the EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, we see successful connections to addresses like &lt;CODE&gt;140.82.121.x&lt;/CODE&gt;&amp;nbsp;that are allowed from the EDL, but also connections to &lt;CODE&gt;20.250.119.67&lt;/CODE&gt; and &lt;CODE&gt;20.250.119.71-73&lt;/CODE&gt;, which are blocked because they're not included in the GitHub EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's interesting is that connecting to these IPs via HTTPS show a certificate for &lt;CODE&gt;github.com&lt;/CODE&gt;, so they appear to be legitimate GitHub infrastructure. However, they also don't seem to be present in GitHub's Meta API (&lt;CODE&gt;&lt;A href="https://api.github.com/meta" target="_blank"&gt;https://api.github.com/meta&lt;/A&gt;&lt;/CODE&gt;), which I would have expected to be the source for the EDL content.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else observed this recently?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are you handling GitHub allowlisting in environments where destination IPs are used for policy decisions? Are you maintaining additional custom EDLs, opening a broader range, or using another approach?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Curious to hear how others deal with this. Thanks!&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 05 Oct 2026 08:50:12 GMT</pubDate>
    <dc:creator>MiBaAveniq</dc:creator>
    <dc:date>2026-10-05T08:50:12Z</dc:date>
    <item>
      <title>Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265600#M127110</link>
      <description>&lt;DIV style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"&gt;
&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we've been using the Palo Alto managed GitHub EDL to allow access to GitHub and recently noticed some connections being blocked because the destination IPs aren't covered by the EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, we see successful connections to addresses like &lt;CODE&gt;140.82.121.x&lt;/CODE&gt;&amp;nbsp;that are allowed from the EDL, but also connections to &lt;CODE&gt;20.250.119.67&lt;/CODE&gt; and &lt;CODE&gt;20.250.119.71-73&lt;/CODE&gt;, which are blocked because they're not included in the GitHub EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's interesting is that connecting to these IPs via HTTPS show a certificate for &lt;CODE&gt;github.com&lt;/CODE&gt;, so they appear to be legitimate GitHub infrastructure. However, they also don't seem to be present in GitHub's Meta API (&lt;CODE&gt;&lt;A href="https://api.github.com/meta" target="_blank"&gt;https://api.github.com/meta&lt;/A&gt;&lt;/CODE&gt;), which I would have expected to be the source for the EDL content.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else observed this recently?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are you handling GitHub allowlisting in environments where destination IPs are used for policy decisions? Are you maintaining additional custom EDLs, opening a broader range, or using another approach?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Curious to hear how others deal with this. Thanks!&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Oct 2026 08:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265600#M127110</guid>
      <dc:creator>MiBaAveniq</dc:creator>
      <dc:date>2026-10-05T08:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265605#M127111</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289745"&gt;@MiBaAveniq&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're correct, if GitHub does not publish the IP address in their Meta API response, PANW’s automated EDL generator will not include it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are different alternative approaches that come to mind:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;App-ID + SSL Decryption:&amp;nbsp;Instead of restricting by IP, structure your Security Policy using App-IDs:&lt;BR /&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;github-base&lt;/LI&gt;
&lt;LI&gt;github-enterprise&lt;/LI&gt;
&lt;LI&gt;git&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Combine this with &lt;/SPAN&gt;SSL Forward Proxy Decryption&lt;SPAN&gt; so PAN-OS can inspect the HTTP Host / SNI headers and allow traffic based on application identity rather than destznation IP.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;URL Filtering / Custom FQDN Objects:&lt;BR /&gt;&lt;STRONG style="font-family: inherit;" data-index-in-node="0" data-path-to-node="6,4,1,0"&gt;&lt;BR /&gt;&lt;/STRONG&gt;If you must restrict destination targets in policy, use FQDN objects (e.g., *.github.com, github.com, *.githubusercontent.com&lt;STRONG style="font-family: inherit;" data-index-in-node="0" data-path-to-node="6,4,1,0"&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;/STRONG&gt;or a custom URL Filtering Profile matching GitHub domains instead of pure IP EDLs. PAN-OS dynamically resolves FQDN objects and updates dataplane IP tables accordingly.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,4,2,0"&gt;Hybrid EDL Strategy (If IP Restrictions Are Required by Compliance):&lt;BR /&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="6,4,2,0"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="6,4,2,1"&gt;If your organization mandates strict destination IP filtering in Security Policy, you will need to append Microsoft Azure Public IP ranges (specifically Azure Cloud IP ranges for the relevant regions) into a secondary custom EDL alongside the Palo Alto / GitHub EDL, though this significantly broadens your destination allowlist.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;BR /&gt;Best,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 09:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265605#M127111</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-10-05T09:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265608#M127112</link>
      <description>&lt;DIV style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"&gt;
&lt;P&gt;Thanks for the suggestions. I agree that App-ID, URL Filtering, FQDN objects and SSL decryption are viable options for HTTPS traffic.&lt;/P&gt;
&lt;P&gt;However, my main concern is Git over SSH, where URL filtering, SNI inspection and SSL decryption are not available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In that scenario, the Palo Alto GitHub EDL seems to be the only practical mechanism to restrict SSH access to GitHub...&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Oct 2026 10:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265608#M127112</guid>
      <dc:creator>MiBaAveniq</dc:creator>
      <dc:date>2026-10-05T10:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265638#M127117</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289745"&gt;@MiBaAveniq&lt;/a&gt;MiBaAveniq As&amp;nbsp;per the Link below you can decrypt the SSH traffic. But then the Rule has to be IP based for the destination.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKgCAK" target="_blank"&gt;How to Implement SSH Decryption on a Palo Alto Networks Device - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 18:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265638#M127117</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2026-10-05T18:42:02Z</dc:date>
    </item>
  </channel>
</rss>

