<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic Block Lists and Spamhaus in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19303#M14089</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cheers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a shame that PA doesn't natively support the the Spamhaus DROP list, as it's only very slightly different from the noted format and is probably one of the most common publicly available (with strong provenance) block lists that is perfectly suited for leveraging in this form of object.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Nov 2012 18:24:12 GMT</pubDate>
    <dc:creator>apackard</dc:creator>
    <dc:date>2012-11-12T18:24:12Z</dc:date>
    <item>
      <title>Dynamic Block Lists and Spamhaus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19301#M14087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know if the Spamhaus format drop lists (that use ";" delimiters to denote descriptive text) are accepted as PA Dynamic Block lists?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.spamhaus.org/drop/drop.txt" title="http://www.spamhaus.org/drop/drop.txt"&gt;http://www.spamhaus.org/drop/drop.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 13:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19301#M14087</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-11-09T13:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Block Lists and Spamhaus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19302#M14088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think you can use any sort of delimiter.&amp;nbsp; It looks like you'll need to quote the entries too.&amp;nbsp; So if the list looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;; Spamhaus DROP List 11/09/12 - (c) 2012 The Spamhaus Project&lt;/P&gt;&lt;P&gt;; Last-Modified: Fri, 9 Nov 2012 14:04:03 GMT&lt;/P&gt;&lt;P&gt;; Expires: Sat, 10 Nov 2012 20:45:42 GMT&lt;/P&gt;&lt;P&gt;5.34.242.0/24 ; SBL154880&lt;/P&gt;&lt;P&gt;14.192.0.0/19 ; SBL123577&lt;/P&gt;&lt;P&gt;14.192.48.0/21 ; SBL131019&lt;/P&gt;&lt;P&gt;14.192.56.0/22 ; SBL131020&lt;/P&gt;&lt;P&gt;31.11.43.0/24 ; SBL113323&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would need to become this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"5.34.242.0/24"&lt;/P&gt;&lt;P&gt;"14.192.0.0/19"&lt;/P&gt;&lt;P&gt;...et cetera&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the on-line help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="H2_Head2" style="color: #000000; font-family: 'Tw Cen MT'; font-size: 18pt; font-weight: bold; margin: 22pt 0px 5pt;"&gt;&lt;A name="1723093"&gt;Dynamic Block Lists&lt;/A&gt;&lt;/P&gt;&lt;P class="NV_Navigation" style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 10pt; font-style: italic; font-weight: bold; margin: 0px 0px 10pt;"&gt;&lt;SPAN class="Wingdings" style="font-family: 'Wingdings 3'; font-size: 10pt; font-style: normal;"&gt;&lt;/SPAN&gt;&lt;A name="1723094"&gt;Objects &amp;gt; Dynamic Block Lists&lt;/A&gt;&lt;/P&gt;&lt;P class="T_Text" style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;A name="1607392"&gt;Use the &lt;/A&gt;&lt;SPAN style="font-weight: bold;"&gt;Dynamic Block Lists&lt;/SPAN&gt; page to create an address object based on an imported list of IP addresses. The source of the list must be a text file and must be located on a web server. You can set the &lt;SPAN style="font-weight: bold;"&gt;Repeat&lt;/SPAN&gt; option to automatically update the list on the device hourly, daily, weekly, or monthly. After creating a dynamic block list object, you can then use the address object in the source and destination fields for security policies. Each&lt;SPAN style="font-size: 11pt;"&gt; &lt;/SPAN&gt;imported list can contain up to 5,000 IP addresses (IPv4 and/or IPv6), IP ranges, or subnets.&lt;/P&gt;&lt;P class="T_Text" style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;A name="1607393"&gt;The list must contain one IP address, range, or subnet per line, for example:&lt;/A&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-family: 'Microsoft Sans Serif'; font-size: 10pt;"&gt;“192.168.80.150/32” indicates one address, and “192.168.80.0/24” indicates all addresses from 192.168.80.0 through 192.168.80.255.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-family: 'Microsoft Sans Serif'; font-size: 10pt;"&gt;Example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-family: 'Microsoft Sans Serif'; font-size: 10pt;"&gt;“2001:db8:123:1::1” or “2001:db8:123:1::/64”&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; font-weight: bold; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-family: 'Microsoft Sans Serif'; font-size: 10pt;"&gt;IP Range:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-family: 'Microsoft Sans Serif'; font-size: 10pt;"&gt;To specify an address range, select &lt;/SPAN&gt;&lt;SPAN style="font-weight: bold;"&gt;IP Range&lt;/SPAN&gt;, and enter a range of addresses. The format is:&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-style: italic;"&gt;ip_address&lt;/SPAN&gt;–&lt;SPAN style="font-style: italic;"&gt;ip_address&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-family: 'Microsoft Sans Serif'; font-size: 10pt;"&gt;where each address can be IPv4 or IPv6.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-family: 'Microsoft Sans Serif'; font-size: 10pt;"&gt;Example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="TB_TableBody" style="color: #000000; font-family: Palatino; font-size: 10pt; margin: 0px 0px 3pt;"&gt;&lt;SPAN style="font-family: 'Microsoft Sans Serif'; font-size: 10pt;"&gt;“2001:db8:123:1::1 - 2001:db8:123:1::22”&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="T_Text" style="color: #000000; font-family: Palatino; font-size: 12pt; margin: 0px 0px 3pt;"&gt;&lt;A name="1626908"&gt; &lt;/A&gt;&lt;/P&gt;&lt;TABLE cellspacing="0" class="TW_TableWide" style="margin: 10pt 0 20pt; padding: 5pt 6pt 3pt; color: #000000; font-family: 'Times New Roman'; font-size: medium;" summary=""&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.5pt; border-top-color: #000000; border-top-style: solid; border-top-width: 2pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TH_TableHeading" style="font-family: 'Tw Cen MT'; font-size: 11pt; font-weight: bold; text-indent: 0pt;"&gt;&lt;A name="1606366"&gt;Field&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.5pt; border-top-color: #000000; border-top-style: solid; border-top-width: 2pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TH_TableHeading" style="font-family: 'Tw Cen MT'; font-size: 11pt; font-weight: bold; text-indent: 0pt;"&gt;&lt;A name="1606368"&gt;Description&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.25pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.5pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TSH_TableSubHeading" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; text-indent: 0pt;"&gt;&lt;A name="1606370"&gt;Name&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.25pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.5pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TB_TableBody" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; margin: 0px 0px 3pt; text-indent: 0pt;"&gt;&lt;A name="1606372"&gt;Enter a name to identify the Dynamic Block List (up to 32 characters). This name will appear when selecting the source or destination in a policy.&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.25pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.25pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TSH_TableSubHeading" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; text-indent: 0pt;"&gt;&lt;A name="1606374"&gt;Description&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.25pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.25pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TB_TableBody" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; margin: 0px 0px 3pt; text-indent: 0pt;"&gt;&lt;A name="1606376"&gt;Enter a description for the block list (up to 255 characters).&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.25pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.25pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TSH_TableSubHeading" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; text-indent: 0pt;"&gt;&lt;A name="1606378"&gt;Source&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.25pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.25pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TB_TableBody" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; margin: 0px 0px 3pt; text-indent: 0pt;"&gt;&lt;A name="1606380"&gt;Enter an HTTP or HTTPS URL path that contains the text file. For example, http:\\1.1.1.1\myfile.txt. You can also enter a UNC server path.&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.25pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.25pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TSH_TableSubHeading" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; text-indent: 0pt;"&gt;&lt;A name="1606382"&gt;Repeat&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.25pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.25pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TB_TableBody" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; margin: 0px 0px 3pt; text-indent: 0pt;"&gt;&lt;A name="1606384"&gt;Specify the frequency in which the list should be imported. You can choose hourly, daily, weekly, or monthly. At the specified interval, the list will be imported into the configuration. A full commit is not needed for this type of update to occur.&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.5pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.25pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TSH_TableSubHeading" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; text-indent: 0pt;"&gt;&lt;A name="1606386"&gt;Test Source URL&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom-color: #000000; border-bottom-style: solid; border-bottom-width: 0.5pt; border-top-color: #000000; border-top-style: solid; border-top-width: 0.25pt; padding: 5pt 6pt 3pt;"&gt;&lt;P class="TB_TableBody" style="font-family: 'Microsoft Sans Serif'; font-size: 9pt; margin: 0px 0px 3pt; text-indent: 0pt;"&gt;&lt;A name="1606388"&gt;Test that the source URL or server path is available.&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 20:49:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19302#M14088</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2012-11-09T20:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Block Lists and Spamhaus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19303#M14089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cheers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a shame that PA doesn't natively support the the Spamhaus DROP list, as it's only very slightly different from the noted format and is probably one of the most common publicly available (with strong provenance) block lists that is perfectly suited for leveraging in this form of object.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2012 18:24:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19303#M14089</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-11-12T18:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Block Lists and Spamhaus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19304#M14090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no need to put quote to an entry.&lt;/P&gt;&lt;P&gt;regarding the spamhaus, you can use a linux web server with a crontab that generate a text file, this command can do the trick:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;curl -L &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.spamhaus.org/drop/drop.txt"&gt;http://www.spamhaus.org/drop/drop.txt&lt;/A&gt;&lt;SPAN&gt; | grep -Eo '([0-9]{1,3}\.){3}[0-9]{1,3}/[0-9]{2}' &amp;gt; /path/to/the/file/spamhaus.txt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can use a crontab to schedule the file update (once a day is enough with spamhaus):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit the crontab file:&lt;/P&gt;&lt;P&gt;crontab -e&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;insert this command (this will update every day at 6:00am the file /path/to/the/file/spamhaus.txt) :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;0 6&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&amp;nbsp; curl -L &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.spamhaus.org/drop/drop.txt"&gt;http://www.spamhaus.org/drop/drop.txt&lt;/A&gt;&lt;SPAN&gt; | grep -Eo '([0-9]{1,3}\.){3}[0-9]{1,3}/[0-9]{2}' &amp;gt; /path/to/the/file/spamhaus.txt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and close the crontab editor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create a dynamic block list object pointing to the correct url to download the generated file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2012 23:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19304#M14090</guid>
      <dc:creator>cviaud</dc:creator>
      <dc:date>2012-11-12T23:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Block Lists and Spamhaus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19305#M14091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks cviaud.&lt;/P&gt;&lt;P&gt;It would be really good if the dynamic objects could accept grep commands so this content parsing could be supported natively - there could be a nice little community creating and sharing rules for publically available block lists.&amp;nbsp; I guess it may also open a door to self-DoS if customers write bad code though!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 08:36:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19305#M14091</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-11-13T08:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Block Lists and Spamhaus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19306#M14092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI, the Spamhaus DROP list is included with the EmergingThreats list. This list is directly importable without any preprocessing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" title="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Apr 2014 14:23:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-and-spamhaus/m-p/19306#M14092</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2014-04-03T14:23:01Z</dc:date>
    </item>
  </channel>
</rss>

