<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Minemeld automatic updates required for future Azure Public IP changes and additions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-automatic-updates-required-for-future-azure-public-ip/m-p/422710#M94906</link>
    <description>&lt;P&gt;We have a JSON file&amp;nbsp; from the URL below which is updated weekly:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/download/confirmation.aspx?id=56519" target="_blank"&gt;https://www.microsoft.com/en-us/download/confirmation.aspx?id=56519&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideally, we would like to pull a list of IPV4 IP addresses out from the section&amp;nbsp;&amp;nbsp;"name": "AzureIoTHub", which needs to be converted into EDL format by MineMeld. The list of IPs can then be referenced in the security policies in Palo Alto.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone how to set up a customised prototype in Minemeld?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jul 2021 16:19:46 GMT</pubDate>
    <dc:creator>Yongjie</dc:creator>
    <dc:date>2021-07-28T16:19:46Z</dc:date>
    <item>
      <title>Minemeld automatic updates required for future Azure Public IP changes and additions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-automatic-updates-required-for-future-azure-public-ip/m-p/422710#M94906</link>
      <description>&lt;P&gt;We have a JSON file&amp;nbsp; from the URL below which is updated weekly:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/download/confirmation.aspx?id=56519" target="_blank"&gt;https://www.microsoft.com/en-us/download/confirmation.aspx?id=56519&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideally, we would like to pull a list of IPV4 IP addresses out from the section&amp;nbsp;&amp;nbsp;"name": "AzureIoTHub", which needs to be converted into EDL format by MineMeld. The list of IPs can then be referenced in the security policies in Palo Alto.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone how to set up a customised prototype in Minemeld?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 16:19:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-automatic-updates-required-for-future-azure-public-ip/m-p/422710#M94906</guid>
      <dc:creator>Yongjie</dc:creator>
      <dc:date>2021-07-28T16:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld automatic updates required for future Azure Public IP changes and additions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-automatic-updates-required-for-future-azure-public-ip/m-p/427062#M94907</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187977"&gt;@Yongjie&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version of MineMeld are you running?&lt;/P&gt;
&lt;P&gt;If you are running one of the laters you should be able to use the build-in miner Azure IPs. In previous version MineMeld was mining old URL that was not providing the what information for what service was used the IP range. But in the recent version (not sure since when) it is supporting service tag.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- You should see azure.cloudIPsWithServiceTags miner prototype&lt;/P&gt;
&lt;P&gt;- You can clone it to create miner, that will mine the entire json file and filter the service you need on the output&lt;/P&gt;
&lt;P&gt;- Using one of the standard output prototype create new and add filter condition to accept only prefixes with service tag of your choise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is example I am using for output only Azure CosmosDB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;infilters:
-   actions:
    - accept
    conditions:
    - __method == 'withdraw'
    name: accept withdraws
-   actions:
    - accept
    conditions:
    - type == 'IPv4'
    - azure_system_service == 'AzureCosmosDB'
    - azure_region  == 'westeurope'
    name: accept AzureCosmosDB IPv4
-   actions:
    - drop
    name: drop all
store_value: true
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note you can check the correct serive name from the original JSON.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 13:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-automatic-updates-required-for-future-azure-public-ip/m-p/427062#M94907</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-08-16T13:24:59Z</dc:date>
    </item>
  </channel>
</rss>

