EDL problem

Reply
L3 Networker

EDL problem

Hi,

I find this error: EDL(my list) Entry not referenced by a rule.

What does it mean? How can I resolve it?

L2 Linker

Re: EDL problem

In Objects > External Dynamic Lists you defined an EDL (e.g. you read a list of malicious addresses from some feed), but none of your policies is referencing it. An EDL would probably end up in the Destination Address part of some policy.
Nothing bad, anyway, your firewall is basically just reading an external list of addresses but it's not using that information anywhere.

L3 Networker

Re: EDL problem

Hi,

I have a rule with many denies IPs. Is maybe for this reason?

Have I to create a special policy for EDL?

L2 Linker

Re: EDL problem

No. A rule with a statically defined list of IPs is not an "external dynamic list". Your configuration is pointing to an external source of addresses, it is reading it, but it's not using it. You can either remove the list from Objects > External Dynamic lists or use it in a policy (if appropriate, of course).

L3 Networker

Re: EDL problem

How can I use it in a policy? In which part of configuration have I to enter?

L2 Linker

Re: EDL problem

Source or destination address. Think of it as an Address group.

L3 Networker

Re: EDL problem

I thought it was enough to insert the EDL instead we also need the security rule. Thaks a lot! Only one last question. Why in the standard Paloalto EDL do you see all the IPs in detail, while in my personalized rules I don't see IPs? In this manner I can't insert any exceptions.

L2 Linker

Re: EDL problem

My firewalls exhibit the same behaviour (PanOS 8.1.10), the list is valid, but the GUI shows no addresses in it. Maybe it's a bug?Schermata 2019-10-29 alle 09.40.38.pngSchermata 2019-10-29 alle 09.40.55.pngSchermata 2019-10-29 alle 09.41.15.pngSchermata 2019-10-29 alle 09.41.50.png

L3 Networker

Re: EDL problem

Yes that's the problem I meant.

Do you know some good lists to use for blocking malicious IPs?

I found http://plonkatronix.com/plonkatronixBL.txt and this URL https://panwdbl.appspot.com/ (I'm investiganting about this).

 

L2 Linker

Re: EDL problem

Not really, I'm sorry. It's something I plan to do, but it's low on my priority list at the moment.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!