<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Dynamic Block List in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68274#M39854</link>
    <description>&lt;P&gt;EBLs or DBLs that I know of can only be refreshed "Dynamically" once an hour. &amp;nbsp;Via CLI you can manually update them:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;" request system external-list refresh name (then the name of your custom list)." &amp;nbsp;The idea to use 4 separare EBLs might be a good idea if you're needing something refreshed more quickly than an hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--edit-- didn't see ibaxter's post already describing the above commands.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Nov 2015 15:52:11 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2015-11-17T15:52:11Z</dc:date>
    <item>
      <title>Custom Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/112#M89</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know how long a custom dynamic block list take to refresh? Is it suppose to refresh\pull every 15 minutes? And if you do a commit does that make the change immediate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my scenario, we are using a custom dynamic block list to add xp pcs to restrict the internet. When the pc is upgraded to Win7 we than remove the ip from the block list. It is now closing in on an hour and multiple commits and the ips are still acting as if they are still part of this list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone one know how long before they will not be read as if they are part of the block list?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 13:37:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/112#M89</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2015-04-02T13:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/113#M90</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry got a head of myself, On the actual list I can set the pulling times but I guess my question does a commit override the pulling time?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 13:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/113#M90</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2015-04-02T13:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68232#M39835</link>
      <description>&lt;P&gt;Yes, a commit will cause an EBL refresh. &amp;nbsp;I just tested this on my box and saw the Pan(w)achrome message pop up saying the EBL refresh was successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also use panxapi.py to refresh the list and also to show what addresses are being blocked whenever I want using these two commands in a script. &amp;nbsp;The IP address and my API key are already included in the panrc file so don't need to be included in these commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;./panxapi.py -Xo 'request system external-list refresh name "DShield_Top_20"'&lt;BR /&gt;./panxapi.py -Xo 'request system external-list show name "DShield_Top_20"'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 15:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68232#M39835</guid>
      <dc:creator>ibaxter</dc:creator>
      <dc:date>2015-11-16T15:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68238#M39838</link>
      <description>&lt;P&gt;I would be intrested to know , do many people use this list ?&lt;/P&gt;
&lt;P&gt;Informaiton as to who updates this list is a little sparse&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 16:49:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68238#M39838</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2015-11-16T16:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68249#M39841</link>
      <description>&lt;P&gt;Very handy to block well known scanners to bring down noise coming from internet (OpenBL for example).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In big environments can be used as whitelist instead.&lt;/P&gt;
&lt;P&gt;For example script will generate list of (physical) domain controllers to a file and firewalls allow active directory specific applications towards this dynamic block list etc.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 23:08:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68249#M39841</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-11-16T23:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68268#M39852</link>
      <description>&lt;P&gt;This list was not practicle for our use so I leveraged the API and the dynamic object group for blocks as changes to these are immediate.&lt;/P&gt;
&lt;P&gt;One work around for the dynamic block list is to clone the list 4-5 times and config each list with a different update time interval. This will mitigate the issue of updates once each hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a feature request in to add additional granularity to the timers and to add an authentication feature as most reptuable black lists subscriptions require authentication.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once PAN delivers this functionality, the dynamic block list will be of more use.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2015 13:53:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68268#M39852</guid>
      <dc:creator>Gun-Slinger</dc:creator>
      <dc:date>2015-11-17T13:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68274#M39854</link>
      <description>&lt;P&gt;EBLs or DBLs that I know of can only be refreshed "Dynamically" once an hour. &amp;nbsp;Via CLI you can manually update them:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;" request system external-list refresh name (then the name of your custom list)." &amp;nbsp;The idea to use 4 separare EBLs might be a good idea if you're needing something refreshed more quickly than an hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--edit-- didn't see ibaxter's post already describing the above commands.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2015 15:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-dynamic-block-list/m-p/68274#M39854</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-11-17T15:52:11Z</dc:date>
    </item>
  </channel>
</rss>

