Our product detects malware in network traffic streams (the product does not really matter here). When we generate what we call an event, we know the source/destination ip/port. We have had some customers ask for automatically putting the external (usualy the source) ip address on a block list. the list of blocked ip's will of course grow over time. Of course i'm totaly new to Palo Alto, so i'm not sure what the best way to automate adding an ip to a block list. In some ways, one could consider our product as a block list feed, but i'm wondering
a) is a block list feed the right way, or is there a better way to add to a list of ip's to block
b)what the appropriate api calls would be to accomplish this.
Any examples, or other pointers would be much appreciated
Solved! Go to Solution.
There are a few that are built in and others you can create/manage yourself.
Check out this article.
This seems simple enough... just create a file that is accessible via a web server. Is there any specific content/format that is needed, or is it just a simple list of one ip per line.
Here is the link that describes the limits and formats:
Each line of an EBL (External Block List) can be an IP address, IP range, or subnet (IPv6 is supported):
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!