Feed / data control

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Feed / data control

L1 Bithead

Use Case: Ofice 365 Access Control

 

What happens if MineMeld deletes all the IPs from a feed, and the firewall sees there are no more IP’s from that feed. Will the traffic be blocked?

What happens on the firewall if there is no data from a feed where there was data from the last time it pulled? Will it delete the local cached copy of the data and then result in the rule no longer working?

1 accepted solution

Accepted Solutions

L7 Applicator

Hi @rchilukuri,

following applies to O365 feed:

1) What happens if MineMeld deletes all the IPs from a feed, and the firewall sees there are no more IP’s from that feed. Will the traffic be blocked? 

This depends on why MineMeld has deleted all the IPs from the feed. If the IPs have been deleted because they disappeared from the orignal feed, then the served list will be empty and PAN-OS will create an empty EDL and the policies with that EDL won't be matched. If instead the MineMeld is "empty" because MineMeld is no longer available, then PAN-OS will use the last retrieved version of the EDL.

 

2) What happens on the firewall if there is no data from a feed where there was data from the last time it pulled?

See 1)

 

3) Can I prevent MineMeld from removing indicators from the EDL ?

Yes, even if this not suggested. You can create a new prototype based on feedHC and change the infilters to drop the withdraw messages.

 

Hope this helps,

luigi

View solution in original post

1 REPLY 1

L7 Applicator

Hi @rchilukuri,

following applies to O365 feed:

1) What happens if MineMeld deletes all the IPs from a feed, and the firewall sees there are no more IP’s from that feed. Will the traffic be blocked? 

This depends on why MineMeld has deleted all the IPs from the feed. If the IPs have been deleted because they disappeared from the orignal feed, then the served list will be empty and PAN-OS will create an empty EDL and the policies with that EDL won't be matched. If instead the MineMeld is "empty" because MineMeld is no longer available, then PAN-OS will use the last retrieved version of the EDL.

 

2) What happens on the firewall if there is no data from a feed where there was data from the last time it pulled?

See 1)

 

3) Can I prevent MineMeld from removing indicators from the EDL ?

Yes, even if this not suggested. You can create a new prototype based on feedHC and change the infilters to drop the withdraw messages.

 

Hope this helps,

luigi

  • 1 accepted solution
  • 3245 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!