- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-01-2023 11:29 PM
I wanted to block ips via using xsoar, on Pan-os panorama. We have integrated xsoar and panoroma but non of the automations provide us a blocking on panorama. In addition to that I tried to give inputs to Block IP Generic v3 playbook(which is provided by palo alto). Our aim is blocking IP **WITHOUT** using edl or static list, which corresponds DAG(dynamic address group) section of your playbook. However we can not see any blocking operations on prisma or any sort of firewall. To sum up, I want to block ips just using panoroma xsoar integration by using Dynamic Address Group. Whenever we are checking ips from panoroma I can only see that xsoar alters corresponding address group but can not add any ip to block.
04-26-2023 11:41 AM
Hi UmutAK, can you confirm if this issue is still occurring? If so, can you please verify if your Dynamic Address group is defined appropriately in the policies you want to commit to?
Also, are you using the following playbook? https://xsoar.pan.dev/docs/reference/playbooks/pan-os-dag-configuration
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!