Blocking Web Advertisements with an External Dynamic List

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Blocking Web Advertisements with an External Dynamic List

L0 Member

Hello everyone,


I am attempting to block web advertisements on our PA-3020. We have two of these devices which utilize Panorama. We have blocked anything categorized as "web-advertisement" on the firewall, which is great, but a ton of ads are still getting through. What we would like to do is as follows:


  • Utilize an external dynamic list (a text file) to block domains
  • When a blocked site is visited, the page will resolve to an "ad blocked" page rather than just not resolving the page at all.


Does anyone have any suggestions we can use? For our typical malware blacklisting, the sites just do not resolve and show a "page cannot be displayed" message. This is logged, which is great, but for the web advertisement blocking, our CIO wants it to show an "Ad Blocked" message. This message works for anything classified as "web-advertisement."


Any suggestions would be greatly appreciated.





L1 Bithead
BTW, Kevin could You share what source of ad domains do You use?



I tried the EDL with the follwoing link :


but this list dosen`t have starts for domains like " *" , I tried another list that have * but it didn`t work

it give me that the EDL is not vaild.


Is the EDL supports Starts ( ex:* ??


any suggestions ?



@Mohamed_Mabrouk: which version of PAN-OS You have installed? Before 7.1 You can use only IP addresses and ranges in EBL, IMHO (look at this



I am using Paloalto 7.1, I added the same EDL but with Plaintext and it works well


This the list that I used , it contains *;showintro=0&startdate%5Bday%5D=&startdate%...



List format requirements

  • List must be a plain text document (no HTML, no PDF, etc.).
  • Scheme is optional, and will be truncated if found – even if it is incomplete.
  • http:// is not needed.
  • Wildcards (*) are supported.
  • Maximum length per line is 1024 characters.
  • Double-byte characters not supported.
  • If specifying a domain, use both formats (as with custom URL categories):
    • *



Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!