<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure ip-range list EDL size in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/383906#M95424</link>
    <description>&lt;P&gt;Hi Marcus,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new with Minemeld and never used the old Azure Miner.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I found the list we get using the new miner very big and investigated further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution I found is to set a filter in the Minemeld processor, selecting only the prefixes having a null value "" into the azure_system_service_list" :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christophe_Savoy_0-1612455781625.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29823i67C2CFC7D8573E60/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Christophe_Savoy_0-1612455781625.png" alt="Christophe_Savoy_0-1612455781625.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This way you get all the "AzureCloud" prefixes, which should be like the old miner...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If that's not enough, you can also play with some "Regional" filters, like this :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christophe_Savoy_1-1612456096905.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29824iD2710226AEE519EB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Christophe_Savoy_1-1612456096905.png" alt="Christophe_Savoy_1-1612456096905.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NB : Do not use this basic filter&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;  - azure_region == 'uksouth'&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because most prefixes appears twice in the .json file, one in the regional section, and a second time in the 'null' section at the end. And the default Miner retains only the last value it sees, i.e (view of the log) :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christophe_Savoy_2-1612456351929.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29825i89AC3AFD5B479F08/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Christophe_Savoy_2-1612456351929.png" alt="Christophe_Savoy_2-1612456351929.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Feb 2021 16:33:08 GMT</pubDate>
    <dc:creator>CSavoy</dc:creator>
    <dc:date>2021-02-04T16:33:08Z</dc:date>
    <item>
      <title>Azure ip-range list EDL size</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/381036#M95422</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I ran into a problem today when expanding a customer's environment. I'd previously set up an EDL pointing to a Minemeld-generated list of all Azure ip-ranges, no problem thus far. I've done this for other customers before without any issue but noticed now that when I used the recommended prototype&amp;nbsp;&lt;SPAN&gt;azure.cloudIPsWithServiceTags it generated a list with some 24000 rows of ip ranges whereas the old one I've used only generated in the region of 3000. So as I expanded the security policies and NAT rules with more references to the EDL, I got this message when pushing the config from Panorama:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Details:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;. Error: Failed to get vsys config, already allocated (131072 bytes)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;. failed to handle CONFIG_UPDATE_START&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;. (Module: device)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;. Commit failed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Which from as best I can gather is down to the config-size growing too large for the VM300's. Anyone here run into the same problem? Or how do you best get around this issue? Set filters to exclude all irrelevant ip-ranges? I should perhaps add that this would be a general rule for all Azure VMs regardless of region to be able to speak directly to Azures backbone services and differentiate it from general internet access so they can access things like Windows Update, activate windows licenses, update Linux VMs etc.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 20:04:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/381036#M95422</guid>
      <dc:creator>MarcusHil</dc:creator>
      <dc:date>2021-01-20T20:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ip-range list EDL size</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/381052#M95423</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;The IP addresses and networks from the Azure servicetag have overlapping networks. Do you see a way to consolidate all IPs first?&lt;/P&gt;
&lt;P&gt;I don't use minemeld, simply use python for my automation tasks.&lt;/P&gt;
&lt;P&gt;In python you would loop over all networks, add them to your bucket&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;bucket = netaddr.IPSet()&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;for ip in ... :&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; bucket.update(netaddr.IPSet([ip, ]))&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;extract the consolidated networks&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;for net in bucket.iter.cidrs():&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; print(net.__str__())&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 17:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/381052#M95423</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-01-21T17:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ip-range list EDL size</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/383906#M95424</link>
      <description>&lt;P&gt;Hi Marcus,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new with Minemeld and never used the old Azure Miner.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I found the list we get using the new miner very big and investigated further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution I found is to set a filter in the Minemeld processor, selecting only the prefixes having a null value "" into the azure_system_service_list" :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christophe_Savoy_0-1612455781625.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29823i67C2CFC7D8573E60/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Christophe_Savoy_0-1612455781625.png" alt="Christophe_Savoy_0-1612455781625.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This way you get all the "AzureCloud" prefixes, which should be like the old miner...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If that's not enough, you can also play with some "Regional" filters, like this :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christophe_Savoy_1-1612456096905.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29824iD2710226AEE519EB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Christophe_Savoy_1-1612456096905.png" alt="Christophe_Savoy_1-1612456096905.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NB : Do not use this basic filter&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;  - azure_region == 'uksouth'&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because most prefixes appears twice in the .json file, one in the regional section, and a second time in the 'null' section at the end. And the default Miner retains only the last value it sees, i.e (view of the log) :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christophe_Savoy_2-1612456351929.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29825i89AC3AFD5B479F08/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Christophe_Savoy_2-1612456351929.png" alt="Christophe_Savoy_2-1612456351929.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 16:33:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/383906#M95424</guid>
      <dc:creator>CSavoy</dc:creator>
      <dc:date>2021-02-04T16:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ip-range list EDL size</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/384102#M95425</link>
      <description>&lt;P&gt;Very cool, I'll give that a try but that looks very much like it would work. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 13:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/384102#M95425</guid>
      <dc:creator>MarcusHil</dc:creator>
      <dc:date>2021-02-05T13:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ip-range list EDL size</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/384709#M95426</link>
      <description>&lt;P&gt;Hi Christophe,&lt;/P&gt;
&lt;P&gt;Where do you see the output in your third screenshot (with the arrows)? Try as I might I can't seem to find it in the logs...&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 07:54:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/384709#M95426</guid>
      <dc:creator>MarcusHil</dc:creator>
      <dc:date>2021-02-09T07:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Azure ip-range list EDL size</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/384710#M95427</link>
      <description>&lt;P&gt;Nevermind, two seconds after posting I found it &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 07:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-ip-range-list-edl-size/m-p/384710#M95427</guid>
      <dc:creator>MarcusHil</dc:creator>
      <dc:date>2021-02-09T07:56:51Z</dc:date>
    </item>
  </channel>
</rss>

