- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-06-2017 12:29 PM
Use Case: Ofice 365 Access Control
What happens if MineMeld deletes all the IPs from a feed, and the firewall sees there are no more IP’s from that feed. Will the traffic be blocked?
What happens on the firewall if there is no data from a feed where there was data from the last time it pulled? Will it delete the local cached copy of the data and then result in the rule no longer working?
02-06-2017 01:02 PM
Hi @rchilukuri,
following applies to O365 feed:
1) What happens if MineMeld deletes all the IPs from a feed, and the firewall sees there are no more IP’s from that feed. Will the traffic be blocked?
This depends on why MineMeld has deleted all the IPs from the feed. If the IPs have been deleted because they disappeared from the orignal feed, then the served list will be empty and PAN-OS will create an empty EDL and the policies with that EDL won't be matched. If instead the MineMeld is "empty" because MineMeld is no longer available, then PAN-OS will use the last retrieved version of the EDL.
2) What happens on the firewall if there is no data from a feed where there was data from the last time it pulled?
See 1)
3) Can I prevent MineMeld from removing indicators from the EDL ?
Yes, even if this not suggested. You can create a new prototype based on feedHC and change the infilters to drop the withdraw messages.
Hope this helps,
luigi
02-06-2017 01:02 PM
Hi @rchilukuri,
following applies to O365 feed:
1) What happens if MineMeld deletes all the IPs from a feed, and the firewall sees there are no more IP’s from that feed. Will the traffic be blocked?
This depends on why MineMeld has deleted all the IPs from the feed. If the IPs have been deleted because they disappeared from the orignal feed, then the served list will be empty and PAN-OS will create an empty EDL and the policies with that EDL won't be matched. If instead the MineMeld is "empty" because MineMeld is no longer available, then PAN-OS will use the last retrieved version of the EDL.
2) What happens on the firewall if there is no data from a feed where there was data from the last time it pulled?
See 1)
3) Can I prevent MineMeld from removing indicators from the EDL ?
Yes, even if this not suggested. You can create a new prototype based on feedHC and change the infilters to drop the withdraw messages.
Hope this helps,
luigi
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!