External Dynamic Lists not working

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

External Dynamic Lists not working

L2 Linker

Hi all,

 

I have configured EDL of type Dynamic URL Lists with the next configuration

 

EDL.png

 

Then in URL filtering profile the ransomwaretracker_URL category is configured as BLOCK and the Profile is applied in the Security rule.

 

It seems configured correctly, I can list the EDL in CLI, but if I try to go to listed URL, it does not blocked.

 

PAN is working with 7.1.2 version.

 

 

Thanks,

Jordi

 

 

 

 

 

 

 

 

 

16 REPLIES 16

the user is running 7.1.2 PAN-OS

ahh my bad. 

l have just tested trying using http, getting redirected to https. If it is listed on firewall through the cli that is fine, should work. Also could run test button to see if you are connected successfully. Should just work. Please follow link posted by BPry:

 

https://live.paloaltonetworks.com/t5/Learning-Articles/Working-with-External-Block-List-EBL-Formats-...

 

Hi all,

 

Thanks for your opinions. The device is a PAN 3020 and I think that the list are supported, the number of entries is ok.

 

https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Videos/PAN-OS-7-1-URL-Filtering-Dynamic-Block-List-E...

 

I have tried to configure the list without https but continues without block the URLs listed in file.

The test source URL is correct, the list can be oppened.

 

The traffic do match in rule with the profile applied.

 

 

 

 

 

 

 

@COMIP I just tried to run that list on my own 3020 and while the link tests okay it wasn't able to actually pull anything from the list; I would assume because of the formatting. Can you run the command request system external-list show name (name) with the correct name of your list and see if there is actually anything within the list? You could also do a refresh instead of a show and monitor the specific job of the DBL refresh and see if it actually completes. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!