<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regarding EDL domain list which is not working. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/regarding-edl-domain-list-which-is-not-working/m-p/432316#M95729</link>
    <description>&lt;P&gt;If the DNS requests are being parsed through HTTPS, then yes, you will need decryption enabled. Most browsers default to DoH these days, so you may want to convince SysAdmin to disable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please also see &lt;A href="https://live.paloaltonetworks.com/t5/threat-vulnerability-discussions/url-wildcard-use/td-p/230893" target="_self"&gt;this thread&lt;/A&gt; for wildcard / domain formatting, which may also be causing issues.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Sep 2021 15:38:45 GMT</pubDate>
    <dc:creator>LAYER_8</dc:creator>
    <dc:date>2021-09-07T15:38:45Z</dc:date>
    <item>
      <title>Regarding EDL domain list which is not working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regarding-edl-domain-list-which-is-not-working/m-p/432245#M95191</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a query where i need to block domain based malicious domains to be blocked with regards to EDL which we have internally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have called the EDL over the Application/URL category of the policy which has the EDL name which consist of certain number of malicious domains which need to be denied.&lt;/P&gt;&lt;P&gt;For this i had not seen any hit counts to be appeared or im not sure if its working.&lt;/P&gt;&lt;P&gt;I need to know how to block or deny malicious domains based upon the EDL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For this do we need to enable decryption?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 12:53:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regarding-edl-domain-list-which-is-not-working/m-p/432245#M95191</guid>
      <dc:creator>Vijaygvasan</dc:creator>
      <dc:date>2021-09-07T12:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding EDL domain list which is not working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regarding-edl-domain-list-which-is-not-working/m-p/432316#M95729</link>
      <description>&lt;P&gt;If the DNS requests are being parsed through HTTPS, then yes, you will need decryption enabled. Most browsers default to DoH these days, so you may want to convince SysAdmin to disable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please also see &lt;A href="https://live.paloaltonetworks.com/t5/threat-vulnerability-discussions/url-wildcard-use/td-p/230893" target="_self"&gt;this thread&lt;/A&gt; for wildcard / domain formatting, which may also be causing issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 15:38:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regarding-edl-domain-list-which-is-not-working/m-p/432316#M95729</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-09-07T15:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding EDL domain list which is not working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regarding-edl-domain-list-which-is-not-working/m-p/432394#M95736</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167254"&gt;@Vijaygvasan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;When you setup the EDL did you set the type to URL or domain? Formatting can also be a major issue if this is the first time you are attempting to use an EDL, so make sure its formatted correctly.&lt;/P&gt;&lt;P&gt;You actually don't need decryption to be able to block domains, but you do have to be mindful of what the firewall will actually see when looking at the traffic. Without decryption you'll only be able to see the domain as presented unencrypted in the handshake.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 17:21:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regarding-edl-domain-list-which-is-not-working/m-p/432394#M95736</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-09-07T17:21:39Z</dc:date>
    </item>
  </channel>
</rss>

