- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
07-19-2023 10:11 AM
How do I block a specific url using edl?
07-19-2023 10:42 AM
Hi @cylusaragao ,
Thank you for writing to live community!
When you configure the Cortex XDR based EDL on firewalls, the firewalls start syncing the data accumulated in form of IPs and URLs from the Cortex XDR EDL list. This list is populated by security investigators and administrators who were able to find some malicious IPs and URL connection from the endpoints during the course of investigation and/or threat hunting.
When these IPs and URLs are added to the list, the firewalls(if configured) fetch the data from the Cortex XDR locations where the EDLs are hosted. Generally these EDL location are in format mentioned below:
https://edl-<subdomain>.xdr.<region>.paloaltonetworks.com/block_list?type=ip https://edl-<subdomain>.xdr.<region>.paloaltonetworks.com/block_list?type=domain |
Once the firewalls get the IP and domains from the EDL, any network connection associated to those IP and URLs are blocked for all the endpoints which are connected to the firewalls configured with the EDL.
Hope this helps!
Please mark the response as "Accept as Solution" if it answers your query.
07-19-2023 11:07 AM
I don't have a firewall, is there a way to configure the edl directly in the cortex?
07-19-2023 06:03 PM
Hi @cylusaragao ,
URL filtering is a Layer 7 mechanism and Cortex operates on Layer 3. For IPs we can suggest using Cortex XDR host firewalls.
For URLs, there is no mechanism as such to block the URL. There is one method to create BIOC rules for incoming, outgoing and failed network connections(do not add the raw packets), and then add the domains to the list. Once created, you can add the BIOC to restrictions profiles.
Please note, we work on process instances termination and not network termination. Hence the above mentioned step is regressive as any network connection made using browsers for the URL will kill the browser itself and not just the network connection. As a result, all other browser tabs will also shutdown. As a result, this is can be done for 1 or 2 URLs but not a very recommended action. It is recommended to setup a firewall configuration for URL filtering.
Hope this helps.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!