- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-02-2015 08:27 AM
Like you, I was curious about using this and have configured a specific outbound rule which is currently allowing the traffic. Monitoring on that specific rule is currently showing outbound DNS, web-browsing and 360-safeguard-update traffic destined for the DShield top 20.
04-02-2015 08:30 AM
So you are currently using the DShield top 20 list on your outbound traffic and have found any benefits from it? Was it easy to configure? Why did you configure it as an outbound rule not and inbound rule? Do you have it as your top rule and have everything passing through it first?
04-02-2015 08:53 AM
It was easy to configure. I followed this document "Subscribing to the DShield Top 20 on a Palo Alto Networks Firewall - SANS Internet Storm Center" but used a https instead of http for obtaining list updates
This initial configuration is a cautious first step in implementing the blocklist. I've only done an initial outbound rule as I wanted to see how much traffic would be matched and what exact types would show up. Like the botnet reporting it is currently giving me some visibility into internal hosts that need to be looked at closer.
I've placed the rule near the top of the inside->outside rules after some of the other existing block rules but before the permit rules start. Based on how this initial testing turns out, I'll look at implementing inbound rules.
04-02-2015 11:51 AM
so you have downloaded the subscription for dshield which is a list of know bad ips to block any thing from the trust side to the untrusted side. You aren't allowing any of the internal traffic to query, contact or connect to anything on that list. Is this list dynamic? When do you plan to add a inbound list?
04-13-2015 08:23 AM
Have you ever used or heard of this list
https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!