<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dynamic block lists / access groups with FQDN support in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-access-groups-with-fqdn-support/m-p/51505#M37891</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if changing the security policy each time is not an option you could either try to set up a dynamic address group which you can alter by using API calls:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6672"&gt;How to Add an IP Address to a Dynamic Address Group using API&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or set up a domain on your internal DNS server where you can change/add the IP addresses as needed (each fqdn object can contain up to 10 ip addresses)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the dynamic address group will probably be the best solution&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Jun 2014 14:57:36 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2014-06-03T14:57:36Z</dc:date>
    <item>
      <title>dynamic block lists / access groups with FQDN support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-access-groups-with-fqdn-support/m-p/51504#M37890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently we have this security policy to allow FTP access. A user who needs FTP access must be part of a special AD group and the FTP server must be part of an address group.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="13757" alt="FTP.png" class="image-0 jive-image" height="75" src="https://live.paloaltonetworks.com/legacyfs/online/13757_FTP.png" style="height: 75px; width: 1500px;" width="1500" /&gt;&lt;/P&gt;&lt;P&gt;The problem is that there are a lot of changes and the responsible person does not have access to the firewall. This should not be changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my idea was to use dynamic block lists or dynamic address groups. But I think they support only IPs. Is there a possibility to use FQDN? If not can you tell me another alternative how to reach my goal?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2014 13:46:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-access-groups-with-fqdn-support/m-p/51504#M37890</guid>
      <dc:creator>LCMember17002</dc:creator>
      <dc:date>2014-06-03T13:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: dynamic block lists / access groups with FQDN support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-access-groups-with-fqdn-support/m-p/51505#M37891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if changing the security policy each time is not an option you could either try to set up a dynamic address group which you can alter by using API calls:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6672"&gt;How to Add an IP Address to a Dynamic Address Group using API&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or set up a domain on your internal DNS server where you can change/add the IP addresses as needed (each fqdn object can contain up to 10 ip addresses)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the dynamic address group will probably be the best solution&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2014 14:57:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-block-lists-access-groups-with-fqdn-support/m-p/51505#M37891</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2014-06-03T14:57:36Z</dc:date>
    </item>
  </channel>
</rss>

