<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spamhaus Domain Block List (DBL) PANOS Integration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31861#M23318</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried to use the XML API directly to get this working but there seems to be an issue with the API:&lt;A href="https://live.paloaltonetworks.com/message/34961"&gt;Custom URL Category update via API returns "Edit breaks config validity" error&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I did get this to work with panxapi using this:&lt;A href="https://live.paloaltonetworks.com/message/16433"&gt;using panxapi to update a custom-url-category profile from a file&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still, I like the idea of the Feature Request so the firewall can update the DBL directly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Oct 2014 14:24:54 GMT</pubDate>
    <dc:creator>breakaway</dc:creator>
    <dc:date>2014-10-30T14:24:54Z</dc:date>
    <item>
      <title>Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31852#M23309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I recently discovered that one of my favorite real time block list providers has a new block list for domains that are found in phishing emails. PANOS has the ability to use a dynamic block list (DBL)/(EBL) external block list, but from what I have gathered there is no way to get my PA to query domains found in the Spamhaus DBL and deny traffic to URL's where the domain is listed in the Spamhaus DBL. I think this would be a fantastic option. What would be the best avenue to suggest this as a future feature to be added?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my opinion the URL filtering on my PA-3020's is good but not great. It does not seem to do well with URL's that point to domains that are specifically addressed by the Spamhaus DBL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.spamhaus.org/dbl/" title="http://www.spamhaus.org/dbl/"&gt;http://www.spamhaus.org/dbl/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you think?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 15:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31852#M23309</guid>
      <dc:creator>vmChad</dc:creator>
      <dc:date>2014-10-28T15:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31853#M23310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi VmChad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following document that should help.&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4146"&gt;Dynamic Block Lists and Spamhaus&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 17:29:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31853#M23310</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-28T17:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31854#M23311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wow I feel like a dope, I searched this site for DBL and did not find the Spamhaus document that you linked to. I should have searched for Spamhaus and saved you some time. Sorry for being "that guy" and thanks for pointing me in the right direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 19:43:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31854#M23311</guid>
      <dc:creator>vmChad</dc:creator>
      <dc:date>2014-10-28T19:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31855#M23312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi vmChad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am glad I was able to help you. Feel free to ask us as many questions as you want. We are here to help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 19:48:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31855#M23312</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-28T19:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31856#M23313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After looking at the solution you linked to I found that I need to clarify. The solution that you suggested only works by referencing a text file that contains IPs/net addresses. The Spamhaus DBL is different is it a domain block list and has a differnt purpose from the &lt;A href="http://www.spamhaus.org/drop/drop.txt" style="font-style: inherit; font-size: 12px; font-family: inherit; color: #316989;" title="http://www.spamhaus.org/drop/drop.txt"&gt;http://www.spamhaus.org/drop/drop.txt&lt;/A&gt; list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the Spamhaus FAQ:"&lt;SPAN style="color: #333333; font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 11px;"&gt;The DBL uses DNS return codes in the 127.0.1.0/24 range. Queries regarding any domain listed in DBL and &lt;/SPAN&gt;&lt;A class="listmenu" href="http://www.spamhaus.org/faq/answers.lasso?section=Spamhaus%20DBL#279" style="color: #333333; font-size: 11px; font-family: Verdana, Arial, Helvetica, sans-serif;"&gt;all IP queries&lt;/A&gt;&lt;SPAN style="color: #333333; font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 11px;"&gt; will return a response code. If no code is returned (NXDOMAIN) the domain is not listed in DBL. DBL return codes in current and future use are:"&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.spamhaus.org/faq/section/Spamhaus%20DBL#277" title="http://www.spamhaus.org/faq/section/Spamhaus%20DBL#277"&gt;http://www.spamhaus.org/faq/section/Spamhaus%20DBL#277&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PANOS Dynamic Block Lists will not currently work with the Spamhaus DBL from what I can tell. It would be awesome if it could work together with the URL filtering database to keep my users from going to URL/domains that are actively being used for phishing and the like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 22:02:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31856#M23313</guid>
      <dc:creator>vmChad</dc:creator>
      <dc:date>2014-10-28T22:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31857#M23314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi vmChad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DBL only supports IP/Network. You can not have URL in it. URL are considered as syntax error and those entries are skipped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First line in provided document says "To support the Spamhaus Drop list with Dynamic Block Lists, you can use a linux web server which will host the text file with all bad IPs/net."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It says IPs/net, hence URLs are not supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 23:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31857#M23314</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-28T23:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31858#M23315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi vmChad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any additional query. I would be more than happy to help you with that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 23:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31858#M23315</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-28T23:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31859#M23316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My original post was about whether or not PANOS would be able to leverage the Spamhaus DBL, which I now know that it will not. My secondary query in that post was what is the best way to submit this as a possible future integration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still think that this would be an awesome feature. While the PAN-DB URL database is pretty good, the Spamhaus DBL is far better at quickly identifying domains that are hosting phishing pages and malware links that are propagated via web links in email and email attachments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are others out there noticing that the PAN-DB is quote slow at identifying phishing URL's? The last time my firewall identified and blocked someone from going to a URL categorized as phishing was on September 23rd. I am certain that actual phishing sites have been access through our PA many times since September 23rd because I regularly access them in a sandbox environment through the PA as I test documents for end users that ask me if an attachment or link is safe. One of the zones on our firewall is for users in a public library to access the internet for free, I would say that it is safe to bet that multiple times per day those users are accessing phishing sites via the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2014 23:02:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31859#M23316</guid>
      <dc:creator>vmChad</dc:creator>
      <dc:date>2014-10-29T23:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31860#M23317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi vmChad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have open FR to add URL in DBL. Ask SE to vote for you. That will serve the purpose.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #333333; font-family: verdana, arial, tahoma, sans-serif;"&gt;Priority:&lt;/STRONG&gt;&lt;SPAN style="color: #333333; font-family: verdana, arial, tahoma, sans-serif;"&gt; Medium &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #333333; font-family: verdana, arial, tahoma, sans-serif;"&gt;FR ID:&lt;/STRONG&gt;&lt;SPAN style="color: #333333; font-family: verdana, arial, tahoma, sans-serif;"&gt; 3070&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: verdana, arial, tahoma, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: verdana, arial, tahoma, sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: verdana, arial, tahoma, sans-serif;"&gt;Hardik Shah&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: verdana, arial, tahoma, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2014 23:28:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31860#M23317</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-29T23:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31861#M23318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried to use the XML API directly to get this working but there seems to be an issue with the API:&lt;A href="https://live.paloaltonetworks.com/message/34961"&gt;Custom URL Category update via API returns "Edit breaks config validity" error&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I did get this to work with panxapi using this:&lt;A href="https://live.paloaltonetworks.com/message/16433"&gt;using panxapi to update a custom-url-category profile from a file&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still, I like the idea of the Feature Request so the firewall can update the DBL directly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 14:24:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31861#M23318</guid>
      <dc:creator>breakaway</dc:creator>
      <dc:date>2014-10-30T14:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31862#M23319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hardik, thank you for opening the FR. I really appreciate it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 16:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31862#M23319</guid>
      <dc:creator>vmChad</dc:creator>
      <dc:date>2014-10-30T16:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Spamhaus Domain Block List (DBL) PANOS Integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31863#M23320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vmchad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Np... Let me know how conversation goes with SE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 16:33:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spamhaus-domain-block-list-dbl-panos-integration/m-p/31863#M23320</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-30T16:33:58Z</dc:date>
    </item>
  </channel>
</rss>

