Dynamic Block Lists and IP's

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Dynamic Block Lists and IP's

Not applicable


I saw this line in an article about Dynamic Block Lists.


"as our threat team identifies malware, they automatically take any URL or IP associated with that threat and will include it as part of the PAN-DB URL filtering database. "


Does this mean that the PAN-DB contains all the IP's that the URL's resolve to? I would not think so since that one IP may have legitimate URL/URI's associated with it. Can someone clarify?


Thanks,

Jim

2 REPLIES 2

L7 Applicator

Hello Jim,

URL categorization takes advantage of a URL filtering database on the firewall that lists the most popular URLs and other URLs for malicious categories. The URL filtering database may be able to resolve requests that the local database is unable to categorize. The default is enabled when using the BrightCloud database. When using the PAN-DB, this option is enabled by default and is not configurable. PAN-DB will not contain all the IP's that the URL's resolve to.

To configure the system response when a URL remains unresolved after a 5 second timeout period, use the Category and Action settings in this window. Select the action for the category “Not resolved URL.

Thanks

L5 Sessionator

The statement is TRUE only for malware URLs /IP addresses identified by the PA Threat Research Team.

PAN-DB does not contain all the IPs associated with a URL.

  • 1814 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!