<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Github EDLs missing IPs? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265709#M127121</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289745"&gt;@MiBaAveniq&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This isn't a PAN issue if Github isn't publishing that they are using the addresses in question. GitHub will need to update things so that they're properly announcing the addresses, and then PAN's EDL will include said addresses.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Oct 2026 13:46:24 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2026-10-06T13:46:24Z</dc:date>
    <item>
      <title>Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265600#M127110</link>
      <description>&lt;DIV style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"&gt;
&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we've been using the Palo Alto managed GitHub EDL to allow access to GitHub and recently noticed some connections being blocked because the destination IPs aren't covered by the EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, we see successful connections to addresses like &lt;CODE&gt;140.82.121.x&lt;/CODE&gt;&amp;nbsp;that are allowed from the EDL, but also connections to &lt;CODE&gt;20.250.119.67&lt;/CODE&gt; and &lt;CODE&gt;20.250.119.71-73&lt;/CODE&gt;, which are blocked because they're not included in the GitHub EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's interesting is that connecting to these IPs via HTTPS show a certificate for &lt;CODE&gt;github.com&lt;/CODE&gt;, so they appear to be legitimate GitHub infrastructure. However, they also don't seem to be present in GitHub's Meta API (&lt;CODE&gt;&lt;A href="https://api.github.com/meta" target="_blank"&gt;https://api.github.com/meta&lt;/A&gt;&lt;/CODE&gt;), which I would have expected to be the source for the EDL content.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else observed this recently?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are you handling GitHub allowlisting in environments where destination IPs are used for policy decisions? Are you maintaining additional custom EDLs, opening a broader range, or using another approach?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Curious to hear how others deal with this. Thanks!&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Oct 2026 08:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265600#M127110</guid>
      <dc:creator>MiBaAveniq</dc:creator>
      <dc:date>2026-10-05T08:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265605#M127111</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289745"&gt;@MiBaAveniq&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're correct, if GitHub does not publish the IP address in their Meta API response, PANW’s automated EDL generator will not include it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are different alternative approaches that come to mind:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;App-ID + SSL Decryption:&amp;nbsp;Instead of restricting by IP, structure your Security Policy using App-IDs:&lt;BR /&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;github-base&lt;/LI&gt;
&lt;LI&gt;github-enterprise&lt;/LI&gt;
&lt;LI&gt;git&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Combine this with &lt;/SPAN&gt;SSL Forward Proxy Decryption&lt;SPAN&gt; so PAN-OS can inspect the HTTP Host / SNI headers and allow traffic based on application identity rather than destznation IP.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;URL Filtering / Custom FQDN Objects:&lt;BR /&gt;&lt;STRONG style="font-family: inherit;" data-index-in-node="0" data-path-to-node="6,4,1,0"&gt;&lt;BR /&gt;&lt;/STRONG&gt;If you must restrict destination targets in policy, use FQDN objects (e.g., *.github.com, github.com, *.githubusercontent.com&lt;STRONG style="font-family: inherit;" data-index-in-node="0" data-path-to-node="6,4,1,0"&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;/STRONG&gt;or a custom URL Filtering Profile matching GitHub domains instead of pure IP EDLs. PAN-OS dynamically resolves FQDN objects and updates dataplane IP tables accordingly.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,4,2,0"&gt;Hybrid EDL Strategy (If IP Restrictions Are Required by Compliance):&lt;BR /&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="6,4,2,0"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="6,4,2,1"&gt;If your organization mandates strict destination IP filtering in Security Policy, you will need to append Microsoft Azure Public IP ranges (specifically Azure Cloud IP ranges for the relevant regions) into a secondary custom EDL alongside the Palo Alto / GitHub EDL, though this significantly broadens your destination allowlist.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;BR /&gt;Best,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 09:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265605#M127111</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-10-05T09:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265608#M127112</link>
      <description>&lt;DIV style="font-family: 'Segoe UI'; font-size: 14px; font-style: normal; font-weight: 400; line-height: 20px;"&gt;
&lt;P&gt;Thanks for the suggestions. I agree that App-ID, URL Filtering, FQDN objects and SSL decryption are viable options for HTTPS traffic.&lt;/P&gt;
&lt;P&gt;However, my main concern is Git over SSH, where URL filtering, SNI inspection and SSL decryption are not available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In that scenario, the Palo Alto GitHub EDL seems to be the only practical mechanism to restrict SSH access to GitHub...&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Oct 2026 10:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265608#M127112</guid>
      <dc:creator>MiBaAveniq</dc:creator>
      <dc:date>2026-10-05T10:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265638#M127117</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289745"&gt;@MiBaAveniq&lt;/a&gt;MiBaAveniq As&amp;nbsp;per the Link below you can decrypt the SSH traffic. But then the Rule has to be IP based for the destination.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKgCAK" target="_blank"&gt;How to Implement SSH Decryption on a Palo Alto Networks Device - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 18:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265638#M127117</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2026-10-05T18:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265672#M127120</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank's for the hint. But this would still not solve my initial problem that the Github EDL is simply not covering all IPs &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What would be the process to report that to PANW? Via ticket? Just wait?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The missing IPs are in another EDL (Azure Cloud) - but I really want to avoid to open another big EDL just for a few single IPs...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 06:00:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265672#M127120</guid>
      <dc:creator>MiBaAveniq</dc:creator>
      <dc:date>2026-10-06T06:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Github EDLs missing IPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265709#M127121</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289745"&gt;@MiBaAveniq&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This isn't a PAN issue if Github isn't publishing that they are using the addresses in question. GitHub will need to update things so that they're properly announcing the addresses, and then PAN's EDL will include said addresses.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 13:46:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/github-edls-missing-ips/m-p/1265709#M127121</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-10-06T13:46:24Z</dc:date>
    </item>
  </channel>
</rss>

