DShield top 20

Reply
Highlighted
L4 Transporter

DShield top 20

Is anyone currently using this dshield top 20 list subscription? How well does it work/ Is anyone blocking inbound, outbound or both? What is the best way to configure it?

Tags (3)
L4 Transporter

Re: DShield top 20

So has anyone used any dynamic block lists? If so how well did they work and what did they work on?

L0 Member

Re: DShield top 20

Like you, I was curious about using this and have configured a specific outbound rule which is currently allowing the traffic. Monitoring on that specific rule is currently showing outbound DNS, web-browsing and 360-safeguard-update traffic destined for the DShield top 20.

L4 Transporter

Re: DShield top 20

So you are currently using the DShield top 20 list on your outbound traffic and have found any benefits from it? Was it easy to configure? Why did you configure it as an outbound rule not and inbound rule? Do you have it as your top rule and have everything passing through it first?

L0 Member

Re: DShield top 20

It was easy to configure. I followed this document "Subscribing to the DShield Top 20 on a Palo Alto Networks Firewall - SANS Internet Storm Center" but used a https instead of http for obtaining list updates

This initial configuration is a cautious first step in implementing the blocklist. I've only done an initial outbound rule as I wanted to see how much traffic would be matched and what exact types would show up. Like the botnet reporting it is currently giving me some visibility into internal hosts that need to be looked at closer.

I've placed the rule near the top of the inside->outside rules after some of the other existing block rules but before the permit rules start. Based on how this initial testing turns out, I'll look at implementing inbound rules.

L4 Transporter

Re: DShield top 20

so you have downloaded the subscription for dshield which is a list of know bad ips to block any thing from the trust side to the untrusted side. You aren't allowing any of the internal traffic to query, contact or connect to anything on that list. Is this list dynamic? When do you plan to add a inbound list?

L4 Transporter

Re: DShield top 20

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!