- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-02-2025
06:41 AM
- last edited on
03-30-2026
04:55 AM
by
banand
Is it somehow possible to load an EDL from a server located in onprem network (not reachable from Internet)? From which interface / IP address does the AWS CNGFW tries to connect to EDL server? Can it make connection from an interface / IP address located in customer VPC? Could not find any documentation for this specific topic.
07-24-2026 12:41 AM
Why don't you just test it and see if it can?
Is your setup Centralized deployment in Security VPC Cloud NGFW for AWS Centralized Deployments ?
07-28-2026 07:53 AM
Actually tested it and confirmed by Palo Alto account engineer:
CNGFW AWS does not support EDL loading from customer network. All EDLs must be hosted in public reachable Internet.
CNGFW Azure supports usage of loopback IP in customer VNET for connection to EDL host
08-02-2026 11:46 PM - edited 08-02-2026 11:49 PM
What about having Panorama to manage the cloud WAF and have the panorama as a VM on-prem as to fetch the EDL to and a VPN tunnel between on-prem and AWS to be able to push the EDL?
You can then connect it to Strata Cloud Manager Panorama CloudConnector Plugin as to have policies in a single place as Panorama is just the middle man in this case.
08-03-2026 05:12 AM
We actually used Panorama plugin to manage CNGFW (both AWS and Azure), but for the EDL download it does not matter as this connection is made from the firewall device itself to configured edl host. In case of AWS, only public reachable edl hosts can be used. For Azure, the edl connection can use service connection via vnet interface (this is not possible in AWS).
08-04-2026 06:21 AM - edited 08-04-2026 06:22 AM
Maybe then you can limit access on the on-prem fw based on the source IP address (Elastic IP.) that the cloud NGFW in AWS will use to connect to your on-prem server? This way nothing else will will be allowed to reach the on prem feed server. You just need DNS record to a public on-prem ip address probably on a firewall or even router with ACL capabilities.
Maybe this limitation comes as the AWS Cloud NGFW is from what I researched based on AWS Gateway Load Balancer setup while the azure cloud NGFW is based on internal and external Azure LB and Palo Alto VM instances between them. Who knows.
08-04-2026 06:31 AM
Of course there would be options to make onprem EDL host reachable over internet and limit it somehow. But in the end we decided to use self managed VM series anyway. CNGFW had too many limitations and management sacrifices for us.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

