Have a PA220 licensed for Wild fire, Threat prevention, and PANDB URL filtering .
Though I had configured the External Dynamic List based on the best practice, I could not get the default PaloAlto Dynamic IP lists feed : Palo Alto Networks - High-risk IP addresses and the Known malicious IP addresses showing up
Could someone please guide me on how to configure the prefined Palo Alto list ?
The default list is not appearing because the PA is not having the Antivirus installed . To get this please run the following command using the CLI.
"request url-filtering download status vendor paloaltonetworks "
Go to Devices\Dynamic Updates and do " check now "
The PA will download the Antivirus -install the same
Viola --- the default Dynamic IP list appears under Objects/External Dynamic List ... 🙂
Palo Alto Networks - High risk IP addresses and
Palo Alto Networks - Known malicious IP addresses
are selectable as source address or destination address in your security rules without any other prior configuration.
You can view them as Predefined in Objects > External Dynamic Lists if you wish
Hope that helps
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!